
DEF CON 33 - Vulns to end your space mission - A. Olchawa, M. Starcik, R. Fradique & A.Boulaich
Source: YouTube · DEFCONConference · published Oct 10, 2025 · 17:34
The video demonstrates critical vulnerabilities in space systems, showing how attackers can exploit weaknesses in ground control systems and satellite software to take control of spacecraft 0:36-0:53.
Key Takeaways:
• Space systems face growing security risks as commercial providers like SpaceX launch thousands of satellites with dual-use potential 0:49-1:53
• Most security research focused on user equipment rather than the critical ground and space segments 2:40-3:13
• Legacy software like NASA's Core Flight System and OpenC3 contains vulnerabilities allowing remote code execution 5:04-5:53
• Live demo shows XSS vulnerability in OpenC3 mission control that can lead to system takeover 8:03-9:41
• Another demo reveals memory management flaws in NASA's Core Flight System enabling spacecraft hijacking 10:08-13:56
The researchers found significant security awareness gaps in the space industry, emphasizing that while space is hard, space security doesn't need to be 17:11-17:14.
Sources:
- 0:36-0:53 Why space systems security is important
- 1:56-2:09 Explanation of space system segments
- 5:04-5:53 Software used in space systems
- 8:03-9:41 OpenC3 vulnerability demo
- 10:08-13:56 NASA Core Flight System vulnerability demo
- 14:13-17:11 Security awareness issues in space industry
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Hi everyone. Uh thanks for joining our talk about the vulnerability research we've been doing on uh space systems. So just quick introduction uh of the team. So my name is Mileno. I'm currently leading the team at uh Vision Space. On stage today with me is Andy. >> Yeah, my name is Andre. Um I've been working for Vision Space since a couple of uh years now. And prior to that I used to work at the European Space Operations Center for uh a little bit over a decade. also in the room, uh, Ricardo on the first row. And unfortunately, Iman had to already go. So, uh, yeah. Uh, why why are we talking about space systems and why do we think it's it has an impact on the wider society and not just uh on on us in the space industry? And what we see is that there is a huge number of satellites being la…