Heap Buffer Overflow in CryptoLib Affects NASA Software Solutions
CVE-2025-29913

8.9HIGH

Key Information:

Vendor

Nasa

Status
Vendor
CVE Published:
17 March 2025

What is CVE-2025-29913?

A heap buffer overflow vulnerability exists in the Crypto_TC_Prep_AAD function of CryptoLib, impacting versions 1.3.3 and earlier. This flaw is caused by the incorrect calculation of the MAC start index during processing, which can lead to an unsigned integer underflow. As a result, an attacker can craft a malicious telecommand frame that accesses out-of-bounds memory, enhancing the risk of Denial of Service attacks or arbitrary code execution. The defect is documented and remains unresolved in the repository.

Affected Version(s)

CryptoLib <= 1.3.3

References

CVSS V4

Score:
8.9
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-29913 : Heap Buffer Overflow in CryptoLib Affects NASA Software Solutions