CVE-2025-25374

CVSS 3.1 Score 7.5 of 10 (high)

Attack Complexity low
Availability high
Confidentiality none
Integrity none
Scope unchanged
Privileges Required none

Details

Published Mar 25, 2025
Updated: Apr 1, 2025
CWE ID 400

Summary

CVE-2025-25374 is a newly identified vulnerability in NASA's cFS (Core Flight System) Aquila. This issue allows an attacker to manipulate the onboard software, causing it to enter a state that prevents the launch of external applications. Consequently, the platform becomes unresponsive and denial of service ensues. The impact of this vulnerability could potentially disrupt critical space missions, necessitating immediate attention and mitigation efforts from NASA and relevant stakeholders.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share