CVE-2025-30216

CVSS 3.1 Score 9.4 of 10 (high)

Details

Published Mar 25, 2025
Updated: Mar 27, 2025
CWE ID 122

Summary

CVE-2025-30216 refers to a Heap Overflow vulnerability in the `Crypto_TM_ProcessSecurity` function of CryptoLib's CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP), used by the core Flight System (cFS) in spacecraft communications with ground stations. Versions 1.3.3 and prior are affected, where a heap buffer is overflowed when processing Secondary Header Length data of TM protocol packets that exceed the packet's total length. This issue can result in arbitrary code execution or system instability due to the adjacent memory being overwritten during the memcpy operation. A patch is available through commit 810fd66d592c883125272fef123c3240db2f170f.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share