📦 Cryptolib

by Nasa

🔍 What is Cryptolib?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-30356

CRITICAL CVSS 9.8 Apr 1, 2025

A heap buffer overflow vulnerability in CryptoLib's SDLS-EP implementation allows attackers to craft malicious frames that cause negative payload lengths to be interpreted as large unsigned values, le...

CVE-2025-30216

CRITICAL CVSS 9.4 Mar 25, 2025

A heap overflow vulnerability in CryptoLib's TM protocol processing allows attackers to trigger arbitrary memory overwrites by sending specially crafted packets with invalid Secondary Header Length va...

CVE-2025-29911

CRITICAL CVSS 9.8 Mar 17, 2025

A critical heap buffer overflow vulnerability in CryptoLib versions 1.3.3 and prior allows attackers to cause denial of service or potentially execute arbitrary code by sending maliciously crafted AOS...

CVE-2025-29913

CRITICAL CVSS 9.8 Mar 17, 2025

A critical heap buffer overflow vulnerability in CryptoLib versions 1.3.3 and prior allows attackers to cause denial of service or potentially execute arbitrary code by sending maliciously crafted tel...

CVE-2025-29909

CRITICAL CVSS 9.8 Mar 17, 2025

A heap buffer overflow vulnerability in CryptoLib's Crypto_TC_ApplySecurity() function allows attackers to craft malicious Telecommand frames that cause out-of-bounds memory writes. This can lead to d...

CVE-2025-64096

HIGH CVSS 8.8 Oct 30, 2025

A stack-based buffer overflow vulnerability in CryptoLib's Crypto_Key_update() function allows remote attackers to trigger memory corruption by sending specially crafted TLV packets with spoofed lengt...

CVE-2025-59534

HIGH CVSS 7.3 Sep 23, 2025

CVE-2025-59534 is a command injection vulnerability in CryptoLib's initialize_kerberos_keytab_file_login() function that allows attackers to execute arbitrary shell commands by injecting malicious inp...

CVE-2025-54878

HIGH CVSS 8.6 Aug 11, 2025

A heap buffer overflow vulnerability in NASA CryptoLib versions 1.4.0 and prior allows attackers to corrupt heap memory by sending specially crafted telecommand frames. This affects spacecraft communi...

CVE-2024-44912

HIGH CVSS 7.5 Sep 27, 2024

NASA CryptoLib v1.3.0 contains an out-of-bounds read vulnerability in the TM subsystem (crypto_tm.c) that could allow attackers to read sensitive memory contents or cause denial of service. This affec...

CVE-2024-44910

HIGH CVSS 7.5 Sep 27, 2024

CVE-2024-44910 is an out-of-bounds read vulnerability in NASA CryptoLib v1.3.0's AOS subsystem that could allow attackers to read sensitive memory contents or cause denial of service. This affects any...

CVE-2025-46673

MEDIUM CVSS 4.9 Apr 27, 2025

NASA CryptoLib versions before 1.3.2 fail to verify the operational state of Security Associations (SAs) before use, potentially allowing attackers to bypass the Space Data Link Security (SDLS) protoc...