Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-29912

Опубликовано: 17 мар. 2025
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. In versions 1.3.3 and prior, an unsigned integer underflow in the Crypto_TC_ProcessSecurity function of CryptoLib leads to a heap buffer overflow. The vulnerability is triggered when the fl (frame length) field in a Telecommand (TC) packet is set to 0. This underflow causes the frame length to be interpreted as 65535, resulting in out-of-bounds memory access. This critical vulnerability can be exploited to cause a denial of service (DoS) or potentially achieve remote code execution. Users of CryptoLib are advised to apply the recommended patch or avoid processing untrusted TC packets until a fix is available.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:nasa:cryptolib:*:*:*:*:*:*:*:*
Версия до 1.4.0 (исключая)

EPSS

Процентиль: 78%
0.01106
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-122
CWE-787

EPSS

Процентиль: 78%
0.01106
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-122
CWE-787