CVE-2025-46675: Medium severity cryptolib vulnerability
Published Apr 27, 2025
·Updated
In NASA CryptoLib before 1.3.2, the key state is not checked before use, potentially leading to spacecraft hijacking.
Affected Software
2 affected components
nasa CryptoLib<1.3.2
nasa CryptoLib<1.3.2
Remediation
Patch Available
Patch Available
Patch Available
Event History
Apr 27, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Oct 7, 57345
Event
via FIRST·11:21 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-46675?
CVE-2025-46675 has a high severity level due to the potential for spacecraft hijacking.
2
How do I fix CVE-2025-46675?
To fix CVE-2025-46675, upgrade to NASA CryptoLib version 1.3.2 or later.
3
What specific issue does CVE-2025-46675 address?
CVE-2025-46675 addresses the lack of key state checks before use in NASA CryptoLib.
4
What are the potential risks of not addressing CVE-2025-46675?
Failing to address CVE-2025-46675 could lead to unauthorized control over spacecraft systems.
5
Which versions of CryptoLib are affected by CVE-2025-46675?
Versions of NASA CryptoLib prior to 1.3.2 are affected by CVE-2025-46675.