CVE-2026-79954

NASA · CryptoLib

NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand receive path due to improper Security Association validation.

Executive summary

An authentication downgrade vulnerability in NASA CryptoLib 1.5.0 allows unauthenticated attackers to bypass critical security checks, posing a high risk to system integrity.

Vulnerability

This vulnerability involves a flaw in the Telecommand receive path where the receiver selects a Security Association based solely on the SPI field without verifying authorization for the frame's GVCID. This allows an unauthenticated attacker to manipulate the processing flow.

Business impact

The flaw carries a CVSS score of 8.7, indicating high severity due to the potential for unauthorized integrity impacts. Exploitation could allow attackers to bypass security mechanisms, leading to unauthorized command execution or data manipulation within sensitive telecommand processes. This poses a significant threat to the operational integrity and reliability of systems utilizing this library.

Remediation

Immediate Action: Consult the official NASA CryptoLib repository or vendor advisory for the release of a patched version, as no fix is currently identified.

Proactive Monitoring: Monitor Telecommand traffic logs for anomalous Security Association selections or frames that fail GVCID validation checks.

Compensating Controls: Implement strict network ingress filtering to restrict access to the Telecommand interface to known, authorized sources only.

Exploitation status

Public Exploit Available: No (unknown)

Analyst recommendation

Given the high CVSS score and the critical nature of the affected software, organizations should prioritize the identification of all instances of CryptoLib 1.5.0 within their environment. Until a vendor patch is available, strict network segmentation and monitoring of the telemetry receive path are essential to mitigate the risk of unauthorized access.

More NASA CVEs

History

  1. Collected by CVE Brief via github
  2. Held for re-check analysis graded thin
  3. Analyst report written

Sources

Originally found and disclosed by Romel Marín, per the CVE Program record.