Home
MEDIUM: 4.9 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:NDefault status
unaffected
Any version before 1.3.2
affected
Description
NASA CryptoLib before 1.3.2 does not check whether the SA is in an operational state before use, possibly leading to a bypass of the Space Data Link Security protocol (SDLS).
Problem types
CWE-913 Improper Control of Dynamically-Managed Code Resources
Product status
Any version before 1.3.2
References
securitybynature.fr/post/hacking-cryptolib/
securitybynature.fr/post/hacking-cryptolib/
github.com/nasa/CryptoLib/compare/v1.3.1...v1.3.2
github.com/nasa/CryptoLib/pull/286
github.com/nasa/CryptoLib/pull/306
github.com/nasa/CryptoLib/compare/v1.3.0...v1.3.1
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.