CVE-2025-46672

LOW

NASA CryptoLib <1.3.2 - Code Injection

Title source: llm
STIX 2.1

Description

NASA CryptoLib before 1.3.2 does not check the OTAR crypto function returned status, potentially leading to spacecraft hijacking.

Scores

CVSS v3 3.5
EPSS 0.0042
EPSS Percentile 33.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-252
Status published
Products (1)
nasa/cryptolib < 1.3.2
Published Apr 27, 2025
Tracked Since Feb 18, 2026