Nasa
Nasa Cryptolib: vulnerabilidades y CVE
Nasa Cryptolib tiene 28 vulnerabilidades publicadas, 12 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE28
Últimos 12 meses12
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-79954 | Alta (8.7) | 0.56% | — | 17 sept 2026 | NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path. The receiver selects the Security Association used for SDLS processing solely from the SPI field inside the… |
| CVE-2026-22697 | Alta (7.5) | 0.53% | — | 10 ene 2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a… |
| CVE-2026-22027 | Media (5.7) | 0.24% | — | 10 ene 2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a… |
| CVE-2026-22026 | Alta (8.2) | 0.61% | — | 10 ene 2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a… |
| CVE-2026-22025 | Media (6.3) | 0.55% | — | 10 ene 2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a… |
| CVE-2026-22024 | Media (6.3) | 0.49% | — | 10 ene 2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a… |
| CVE-2026-22023 | Alta (8.2) | 0.58% | — | 10 ene 2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a… |
| CVE-2026-21900 | Alta (8.2) | 0.58% | — | 10 ene 2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a… |
| CVE-2026-21899 | Media (4.9) | 0.35% | — | 10 ene 2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a… |
| CVE-2026-21898 | Alta (8.2) | 0.46% | — | 10 ene 2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a… |
| CVE-2026-21897 | Alta (7.3) | 0.29% | — | 10 ene 2026 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a… |
| CVE-2025-64096 | Alta (8.8) | 0.52% | — | 30 oct 2025 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a… |
| CVE-2025-59534 | Alta (7.8) | 0.91% | — | 23 sept 2025 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a… |
| CVE-2025-54878 | Alta (8.6) | 0.39% | — | 11 ago 2025 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a… |
| CVE-2025-46675 | Media (4.2) | 0.35% | — | 27 abr 2025 | In NASA CryptoLib before 1.3.2, the key state is not checked before use, potentially leading to spacecraft hijacking. |
| CVE-2025-46674 | Crítica (9.9) | 0.60% | — | 27 abr 2025 | NASA CryptoLib before 1.3.2 uses Extended Procedures that are a Work in Progress (not intended for use during flight), potentially leading to a keystream oracle. |
| CVE-2025-46673 | Crítica (9.9) | 0.50% | — | 27 abr 2025 | NASA CryptoLib before 1.3.2 does not check whether the SA is in an operational state before use, possibly leading to a bypass of the Space Data Link Security protocol (SDLS). |
| CVE-2025-46672 | Alta (8.8) | 0.53% | — | 27 abr 2025 | NASA CryptoLib before 1.3.2 does not check the OTAR crypto function returned status, potentially leading to spacecraft hijacking. |
| CVE-2025-30356 | Crítica (9.3) | 0.65% | — | 1 abr 2025 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a… |
| CVE-2025-30216 | Crítica (9.1) | 2.6% | — | 25 mar 2025 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a… |
| CVE-2025-29913 | Alta (8.9) | 0.72% | — | 17 mar 2025 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a… |
| CVE-2025-29912 | Alta (8.9) | 1.1% | — | 17 mar 2025 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a… |
| CVE-2025-29911 | Alta (8.9) | 0.74% | — | 17 mar 2025 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a… |
| CVE-2025-29910 | Media (5.5) | 0.49% | — | 17 mar 2025 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a… |
| CVE-2025-29909 | Alta (8.9) | 1.1% | — | 17 mar 2025 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a… |
| CVE-2024-44912 | Alta (7.5) | 0.49% | — | 27 sept 2024 | NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the TM subsystem (crypto_tm.c). |
| CVE-2024-44911 | Alta (7.5) | 0.52% | — | 27 sept 2024 | NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the TC subsystem (crypto_tc.c). |
| CVE-2024-44910 | Alta (7.5) | 0.53% | — | 27 sept 2024 | NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the AOS subsystem (crypto_aos.c). |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.