PT-2026-2128 · Cryptolib · Cryptolib
Finder16
·
Publicado
2026-01-10
·
Atualizado
2026-01-15
·
CVE-2026-21898
CVSS v3.1
8.2
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
CryptoLib versions prior to 1.4.3
Description
CryptoLib is a software solution that uses the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft and a ground station. Prior to version 1.4.3, the
Crypto AOS ProcessSecurity function does not perform valid bounds checking when parsing AOS frame hashes, leading to a potential issue.Recommendations
Versions prior to 1.4.3 should be updated to version 1.4.3 or later.
Exploit
Correção
Out of bounds Read
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cryptolib