Vulnerability Description
NASA CryptoLib before 1.3.2 does not check whether the SA is in an operational state before use, possibly leading to a bypass of the Space Data Link Security protocol (SDLS).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nasa | Cryptolib | < 1.3.2 |
Related Weaknesses (CWE)
References
- https://github.com/nasa/CryptoLib/compare/v1.3.0...v1.3.1Product
- https://github.com/nasa/CryptoLib/compare/v1.3.1...v1.3.2Product
- https://github.com/nasa/CryptoLib/pull/286Product
- https://github.com/nasa/CryptoLib/pull/306Product
- https://securitybynature.fr/post/hacking-cryptolib/ExploitPress/Media Coverage
- https://securitybynature.fr/post/hacking-cryptolib/ExploitPress/Media Coverage
FAQ
What is CVE-2025-46673?
CVE-2025-46673 is a vulnerability with a CVSS score of 4.9 (MEDIUM). NASA CryptoLib before 1.3.2 does not check whether the SA is in an operational state before use, possibly leading to a bypass of the Space Data Link Security protocol (SDLS).
How severe is CVE-2025-46673?
CVE-2025-46673 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-46673?
Check the references section above for vendor advisories and patch information. Affected products include: Nasa Cryptolib.