CVE-2025-46672
CVSS 3.1 Score 3.5 of 10 (low)
Details
Published Apr 27, 2025
Updated: Apr 29, 2025
CWE ID 252
Summary
CVE-2025-46672 is a vulnerability affecting NASA's CryptoLib software before version 1.3.2. This issue arises from the lack of validation of the OTAR crypto function's returned status. An attacker who successfully exploits this weakness could potentially hijack spacecraft systems that rely on this software for cryptographic protections. The consequences could be severe, making it crucial for organizations using NASA's CryptoLib to update to a patched version as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- NASA