ESA SPACE-SHIELD
T2007.006
enhancement

Software vulnerabilities

Parent: T2007

Description

Exploiting unpatched/Outdated/Legacy COTS software deployed among the platform. COTS products are often highly complex, some of them involving tens of millions of lines of code, so that no one knows their content and behavior in detail. SDRs introduce protocol-independent software vulnerabilities into the communication system. (Citation: SRC012)

Mapped SPARTA techniques

5 techniques

  • EX-0009Exploit Code FlawsST0004
    addresses
    high

    T2007.006 'Software vulnerabilities' is the direct cross-framework counterpart of EX-0009 Exploit Code Flaws — both describe exploiting unpatched/outdated/legacy software defects, with explicit attention to COTS components running on space systems.

  • EX-0009.01Flight SoftwareST0004
    addresses
    moderate

    T2007.006 'Software vulnerabilities' covers exploiting unpatched/legacy COTS software — directly aligned with EX-0009.01's flight-software defects (unchecked lengths, arithmetic overflows, format-string misuse, race conditions in command/telemetry handlers).

  • EX-0009.02Operating SystemST0004
    addresses
    moderate

    T2007.006 covers exploiting software vulnerabilities — applies to OS-layer exploitation when the underlying weaknesses are in unpatched OS components.

  • T2007.006 'Software vulnerabilities' is the direct cross-framework counterpart of EX-0009.03 — both describe matching component versions to publicly/privately known defects in COTS/FOSS components.

  • RD-0003.01Exploit/PayloadST0002
    addresses
    high

    T2007.006 'Software vulnerabilities' covers obtaining/exploiting unpatched COTS — directly aligned with RD-0003.01 acquiring exploit code targeting RTOS/middleware/ground services.

Cite as SafeMode Space, space-shield T2007.006.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.