CVE-2025-46673 Details
Description
NASA CryptoLib before 1.3.2 does not check whether the SA is in an operational state before use, possibly leading to a bypass of the Space Data Link Security protocol (SDLS).
A vulnerability in NASA CryptoLib versions prior to 1.3.2 allows for a bypass of the Space Data Link Security (SDLS) protocol. This issue arises because the software does not verify whether a Security Association (SA) is operational before use. The vulnerability can be exploited to send unauthorized telecommands to a spacecraft's Onboard Computer, potentially leading to unauthorized actions or control of the spacecraft.
Users are advised to update to NASA CryptoLib version 1.3.2 or later, where this vulnerability has been addressed by implementing checks to ensure that Security Associations are in an operational state before use.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 29, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://securitybynature.fr/post/hacking-cryptolib/ | CISA-ADP | ExploitPress/Media Coverage |
| https://github.com/nasa/CryptoLib/compare/v1.3.0...v1.3.1 | [email protected] | Product |
| https://github.com/nasa/CryptoLib/compare/v1.3.1...v1.3.2 | [email protected] | Product |
| https://github.com/nasa/CryptoLib/pull/286 | [email protected] | Product |
| https://github.com/nasa/CryptoLib/pull/306 | [email protected] | Product |
| https://securitybynature.fr/post/hacking-cryptolib/ | [email protected] | ExploitPress/Media Coverage |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-913 | Improper Control of Dynamically-Managed Code Resources | [email protected] |
| CWE-913 | Improper Control of Dynamically-Managed Code Resources | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| nasa cryptolib | < 1.3.2 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 29, 2025 | Initial Analysis | [email protected] |
| Apr 29, 2025 | CVE Modified | CISA-ADP |
| Apr 27, 2025 | New CVE Received | [email protected] |