Heap Buffer Overflow Vulnerability in CryptoLib for Space Communications
CVE-2025-29909

8.9HIGH

Key Information:

Vendor

Nasa

Status
Vendor
CVE Published:
17 March 2025

What is CVE-2025-29909?

CryptoLib, utilized for securing communications in space applications, has a vulnerability that allows attackers to exploit a heap buffer overflow through the Crypto_TC_ApplySecurity() function. This exploitation occurs when an attacker crafts a malicious telecommand frame leading to potential out-of-bounds memory writes. Systems using CryptoLib for telecommand processing that do not implement strict validation on incoming frames are particularly at risk. Such vulnerabilities can cause service interruptions or even unauthorized remote code execution, particularly affecting satellite ground stations and mission control software. A remediation patch is available to address this issue.

Affected Version(s)

CryptoLib <= 1.3.3

References

CVSS V4

Score:
8.9
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-29909 : Heap Buffer Overflow Vulnerability in CryptoLib for Space Communications