Description
NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path. The receiver selects the Security Association used for SDLS processing solely from the SPI field inside the incoming frame, but it does not verify that the selected SA is authorized for the frame's GVCID.
Published: 2026-09-18
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Authentication downgrade allowing unauthorized Security Associations
Action: Patch Now
AI Analysis

Impact

NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand receive path. The receiver selects the Security Association used for SDLS processing solely from the SPI field inside the incoming frame, but it does not verify that the selected SA is authorized for the frame's GVCID. This flaw allows an attacker to send a frame with an SPI that references a Security Association valid for a different GVCID, causing the system to authenticate and process the frame under the wrong Security Association. The result is that the system accepts traffic from an unauthorized source under a valid Security Association, disrupting the intended authentication mechanism.

Affected Systems

The vulnerability affects NASA CryptoLib version 1.5.0 running on Linux, macOS, and Windows platforms.

Risk and Exploitability

The CVSS score of 8.7 reflects a high severity for an authentication bypass. The EPSS score of less than 1% indicates a low probability of exploitation. The vulnerability is not listed in CISA KEV catalog. The attack vector is remote, via the Telecommand interface; an attacker needs only to send a crafted frame over the network. Successful exploitation can result in acceptance of traffic under an unauthorized Security Association, potentially undermining authentication integrity.

Generated by OpenCVE AI on September 19, 2026 at 22:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a patched version of CryptoLib that includes the GVCID verification fix.
  • Reconfigure the Telecommand receiver to validate the selected Security Association against the frame’s GVCID before processing frames.
  • Implement network monitoring or intrusion detection rules to detect and block frames where the SPI does not match the expected GVCID.
  • If upgrade or configuration changes cannot be applied immediately, isolate the CryptoLib process and restrict Telecommand access to trusted hosts only.

Generated by OpenCVE AI on September 19, 2026 at 22:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Description NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path. The receiver selects the Security Association used for SDLS processing solely from the SPI field inside the incoming frame, but it does not verify that the selected SA is authorized for the frame's GVCID.
Title NASA CryptoLib 1.5.0 - TC receive path accepts Security Associations from the wrong GVCID
First Time appeared Nasa
Nasa cryptolib
Weaknesses CWE-306
CPEs cpe:2.3:a:nasa:cryptolib:1.5.0:*:linux:*:*:*:*:*
cpe:2.3:a:nasa:cryptolib:1.5.0:*:macos:*:*:*:*:*
cpe:2.3:a:nasa:cryptolib:1.5.0:*:windows:*:*:*:*:*
Vendors & Products Nasa
Nasa cryptolib
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Fluid Attacks

Published:

Updated: 2026-09-18T19:58:55.144Z

Reserved: 2026-08-25T15:27:48.157Z

Link: CVE-2026-79954

cve-icon Vulnrichment

Updated: 2026-09-18T19:58:50.003Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T01:16:56.120

Modified: 2026-09-18T20:17:23.097

Link: CVE-2026-79954

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:45:06Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function