CVE-2026-79954 PUBLISHED

NASA CryptoLib 1.5.0 - TC receive path accepts Security Associations from the wrong GVCID

Assigner: Fluid Attacks
Reserved: 25.08.2026 Published: 18.09.2026 Updated: 18.09.2026

NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path. The receiver selects the Security Association used for SDLS processing solely from the SPI field inside the incoming frame, but it does not verify that the selected SA is authorized for the frame's GVCID.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor NASA
Product CryptoLib
Versions Default: unaffected
  • Version 1.5.0 is affected

Credits

  • Romel Marín finder

References

Problem Types

  • CWE-306 Missing Authentication for Critical Function CWE

Impacts

  • CAPEC-114 Authentication Abuse