CVE-2025-46672

LOW

NASA CryptoLib <1.3.2 - Code Injection

Title source: llm
STIX 2.1

Description

NASA CryptoLib before 1.3.2 does not check the OTAR crypto function returned status, potentially leading to spacecraft hijacking.

Scores

CVSS v3 3.5
EPSS 0.0020
EPSS Percentile 41.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-252
Status published
Products (1)
nasa/cryptolib < 1.3.2
Published Apr 27, 2025
Tracked Since Feb 18, 2026