PT-2025-17969 · Nasa · Nasa Cryptolib

Published

2025-04-27

·

Updated

2025-04-28

·

CVE-2025-46672

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NASA CryptoLib versions prior to 1.3.2
Description The issue is related to the OTAR crypto function in NASA CryptoLib, where the returned status is not checked, potentially leading to spacecraft hijacking.
Recommendations For NASA CryptoLib versions prior to 1.3.2, update to version 1.3.2 or later to resolve the issue. As a temporary workaround, consider implementing additional checks on the OTAR crypto function returned status to prevent potential hijacking.

Exploit

Fix

Unchecked Return Value

Weakness Enumeration

Related Identifiers

CVE-2025-46672

Affected Products

Nasa Cryptolib