Home
LOW: 3.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:NDefault status
unaffected
Any version before 1.3.2
affected
Description
NASA CryptoLib before 1.3.2 does not check the OTAR crypto function returned status, potentially leading to spacecraft hijacking.
Problem types
CWE-252 Unchecked Return Value
Product status
Any version before 1.3.2
References
securitybynature.fr/post/hacking-cryptolib/
github.com/nasa/CryptoLib/pull/360
securitybynature.fr/post/hacking-cryptolib/
github.com/nasa/CryptoLib/compare/v1.3.1...v1.3.2