Keystream Oracle Vulnerability in NASA CryptoLib Software
CVE-2025-46674

9.9CRITICAL

Key Information:

Vendor

Nasa

Status
Vendor
CVE Published:
27 April 2025

What is CVE-2025-46674?

NASA's CryptoLib, prior to version 1.3.2, incorporates Extended Procedures that were not meant for operational use, particularly during flight missions. This design flaw can potentially lead to a keystream oracle, exposing vulnerabilities that compromise the integrity of cryptographic operations. It is crucial for organizations utilizing CryptoLib to update to the latest version to safeguard against potential exploits.

Affected Version(s)

CryptoLib 0 < 1.3.2

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

.
CVE-2025-46674 : Keystream Oracle Vulnerability in NASA CryptoLib Software