CVE-2025-46672

CVSS 3.1 Score 3.5 of 10 (low)

Details

Published Apr 27, 2025
Updated: Apr 29, 2025
CWE ID 252

Summary

CVE-2025-46672 is a vulnerability affecting NASA's CryptoLib software before version 1.3.2. This issue arises from the lack of validation of the OTAR crypto function's returned status. An attacker who successfully exploits this weakness could potentially hijack spacecraft systems that rely on this software for cryptographic protections. The consequences could be severe, making it crucial for organizations using NASA's CryptoLib to update to a patched version as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share