Description
NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path. The receiver selects the Security Association used for SDLS processing solely from the SPI field inside the incoming frame, but it does not verify that the selected SA is authorized for the frame's GVCID.
Published: 2026-09-18
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Description NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path. The receiver selects the Security Association used for SDLS processing solely from the SPI field inside the incoming frame, but it does not verify that the selected SA is authorized for the frame's GVCID.
Title NASA CryptoLib 1.5.0 - TC receive path accepts Security Associations from the wrong GVCID
First Time appeared Nasa
Nasa cryptolib
Weaknesses CWE-306
CPEs cpe:2.3:a:nasa:cryptolib:1.5.0:*:linux:*:*:*:*:*
cpe:2.3:a:nasa:cryptolib:1.5.0:*:macos:*:*:*:*:*
cpe:2.3:a:nasa:cryptolib:1.5.0:*:windows:*:*:*:*:*
Vendors & Products Nasa
Nasa cryptolib
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Fluid Attacks

Published:

Updated: 2026-09-18T19:58:55.144Z

Reserved: 2026-08-25T15:27:48.157Z

Link: CVE-2026-79954

cve-icon Vulnrichment

Updated: 2026-09-18T19:58:50.003Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T01:16:56.120

Modified: 2026-09-18T20:17:23.097

Link: CVE-2026-79954

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T02:45:16Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function