CVE-2025-46674: Critical severity cryptolib vulnerability
Published Apr 27, 2025
·Updated
NASA CryptoLib before 1.3.2 uses Extended Procedures that are a Work in Progress (not intended for use during flight), potentially leading to a keystream oracle.
Affected Software
2 affected components
nasa CryptoLib<1.3.2
nasa CryptoLib<1.3.2
Remediation
Patch Available
Event History
Apr 27, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeakness
Oct 7, 57345
Event
via FIRST·11:21 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-46674?
CVE-2025-46674 is categorized as having a high severity due to the potential exploitation of a keystream oracle.
2
How do I fix CVE-2025-46674?
To fix CVE-2025-46674, upgrade NASA CryptoLib to version 1.3.2 or later.
3
What is the impact of CVE-2025-46674?
The impact of CVE-2025-46674 may allow unauthorized access to sensitive data through keystream vulnerabilities.
4
What software versions are affected by CVE-2025-46674?
CVE-2025-46674 affects NASA CryptoLib versions prior to 1.3.2.
5
Is CVE-2025-46674 a known vulnerability in operational systems?
Yes, CVE-2025-46674 contains extended procedures that were not intended for use during flight operations.