Description
NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path. The receiver selects the Security Association used for SDLS processing solely from the SPI field inside the incoming frame, but it does not verify that the selected SA is authorized for the frame's GVCID.
Published: 2026-09-18
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Description NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path. The receiver selects the Security Association used for SDLS processing solely from the SPI field inside the incoming frame, but it does not verify that the selected SA is authorized for the frame's GVCID.
Title NASA CryptoLib 1.5.0 - TC receive path accepts Security Associations from the wrong GVCID
First Time appeared Nasa
Nasa cryptolib
Weaknesses CWE-306
CPEs cpe:2.3:a:nasa:cryptolib:1.5.0:*:linux:*:*:*:*:*
cpe:2.3:a:nasa:cryptolib:1.5.0:*:macos:*:*:*:*:*
cpe:2.3:a:nasa:cryptolib:1.5.0:*:windows:*:*:*:*:*
Vendors & Products Nasa
Nasa cryptolib
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Fluid Attacks

Published:

Updated: 2026-09-18T00:26:28.854Z

Reserved: 2026-08-25T15:27:48.157Z

Link: CVE-2026-79954

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-18T01:16:56.120

Modified: 2026-09-18T01:16:56.120

Link: CVE-2026-79954

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses