PT-2025-17970 · Nasa · Nasa Cryptolib

Antonin Boulnois

·

Published

2025-04-27

·

Updated

2026-01-28

·

CVE-2025-46673

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NASA CryptoLib versions prior to 1.3.2
Description The issue is related to NASA CryptoLib not checking whether the SA is in an operational state before use. This could possibly lead to a bypass of the Space Data Link Security protocol (SDLS).
Recommendations For versions prior to 1.3.2, update to version 1.3.2 or later to resolve the issue. As a temporary workaround, consider implementing additional checks to ensure the SA is in an operational state before use.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-46673

Affected Products

Nasa Cryptolib