CVE-2024-54129: Nasa-Jpl Ion-Dtn

Critical severity, CVSS 9.2. EPSS: 0.4% chance of exploitation in the next 30 days.

The NASA’s Interplanetary Overlay Network (ION) is an implementation of Delay/Disruption Tolerant Networking (DTN). A vulnerability exists in the version ION-DTN BPv7 implementation version 4.1.3 when receiving a bundle with an improper reference to the imc scheme with valid Service-Specific Part (SSP) in their Previous Node Block. The vulnerability can cause ION to become unresponsive. This vulnerability is fixed in 4.1.3s.

Affected products

  • Nasa-Jpl Ion-Dtn: before 4.1.3s (fixed in 4.1.3s)

Published 2024-12-05. Last modified 2026-06-17.