Home
LOW: 3.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:NDefault status
unaffected
Any version before 1.3.2
affected
Description
In NASA CryptoLib before 1.3.2, the key state is not checked before use, potentially leading to spacecraft hijacking.
Problem types
CWE-913 Improper Control of Dynamically-Managed Code Resources
Product status
Any version before 1.3.2
References
securitybynature.fr/post/hacking-cryptolib/
securitybynature.fr/post/hacking-cryptolib/
github.com/nasa/CryptoLib/compare/v1.3.1...v1.3.2
github.com/nasa/CryptoLib/pull/358
github.com/nasa/CryptoLib/pull/359