CVE-2025-46672: High severity cryptolib vulnerability
Published Apr 27, 2025
·Updated
NASA CryptoLib before 1.3.2 does not check the OTAR crypto function returned status, potentially leading to spacecraft hijacking.
Affected Software
2 affected components
nasa CryptoLib<1.3.2
nasa CryptoLib<1.3.2
Event History
Apr 27, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeakness
Oct 7, 57345
Event
via FIRST·11:19 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-46672?
CVE-2025-46672 is considered a critical vulnerability due to its potential to allow spacecraft hijacking.
2
How do I fix CVE-2025-46672?
To fix CVE-2025-46672, update NASA CryptoLib to version 1.3.2 or later.
3
What is the impact of CVE-2025-46672?
The impact of CVE-2025-46672 may include unauthorized access to spacecraft controls.
4
Who is affected by CVE-2025-46672?
CVE-2025-46672 affects all users of NASA CryptoLib versions prior to 1.3.2.
5
What type of vulnerability is CVE-2025-46672?
CVE-2025-46672 is an access control vulnerability related to the OTAR crypto function.