Impact
NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand receive path. The receiver selects the Security Association used for SDLS processing solely from the SPI field inside the incoming frame, but it does not verify that the selected SA is authorized for the frame's GVCID. This flaw allows an attacker to send a frame with an SPI that references a Security Association valid for a different GVCID, causing the system to authenticate and process the frame under the wrong Security Association. The result is that the system accepts traffic from an unauthorized source under a valid Security Association, disrupting the intended authentication mechanism.
Affected Systems
The vulnerability affects NASA CryptoLib version 1.5.0 running on Linux, macOS, and Windows platforms.
Risk and Exploitability
The CVSS score of 8.7 reflects a high severity for an authentication bypass. The EPSS score of less than 1% indicates a low probability of exploitation. The vulnerability is not listed in CISA KEV catalog. The attack vector is remote, via the Telecommand interface; an attacker needs only to send a crafted frame over the network. Successful exploitation can result in acceptance of traffic under an unauthorized Security Association, potentially undermining authentication integrity.
OpenCVE Enrichment