CVE-2024-44910

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Sep 27, 2024
Updated: Mar 19, 2025
CWE ID 125

Summary

CVE-2024-44910 is a newly disclosed vulnerability affecting NASA's CryptoLib v1.3.0. The issue lies in the AOS (Advanced Orbit Determination Subsystem) component of crypto_aos.c. An attacker can exploit this Out-of-Bounds read vulnerability to read memory outside the intended bounds, potentially leading to the exposure of sensitive data or system crashes. NASA has released an update to address this security flaw, and users are strongly urged to apply it as soon as possible to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share