CVE-2025-54878
Last modified
CVE-2025-54878 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. A heap buffer overflow vulnerability exists in NASA CryptoLib version 1.4.0 and prior in the IV setup logic for telecommand frames. EPSS estimates a 0.36% chance of exploitation in the next 30 days.
Description
CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. A heap buffer overflow vulnerability exists in NASA CryptoLib version 1.4.0 and prior in the IV setup logic for telecommand frames. The problem arises from missing bounds checks when copying the Initialization Vector (IV) into a freshly allocated buffer. An attacker can supply a crafted TC frame that causes the library to write one byte past the end of the heap buffer, leading to heap corruption and undefined behaviour. An attacker supplying a malformed telecommand frame can corrupt heap memory. This leads to undefined behaviour, which could manifest itself as a crash (denial of service) or more severe exploitation. This issue has been patched in version 1.4.0.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nasa | Cryptolib | < 1.4.1 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-54878?
How severe is CVE-2025-54878?
How do I fix CVE-2025-54878?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-54872onion-site-template is a complete, scalable tor hidden servi…8.7
- CVE-2025-54873RISC Zero is a zero-knowledge verifiable general computing p…2.7
- CVE-2025-54874OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG from…9.8
- CVE-2025-54875FreshRSS is a free, self-hostable RSS aggregator. In version…9.8
- CVE-2025-54876The Janssen Project is an open-source identity and access ma…6.9
- CVE-2025-54877Tuleap is an Open Source Suite created to facilitate managem…5.3
- CVE-2025-54879Mastodon is a free, open-source social network server based …7.5
- CVE-2025-5488The WP Masonry & Infinite Scroll plugin for WordPress is vul…5.4
- CVE-2025-54880Mermaid is a JavaScript based diagramming and charting tool …6.1
- CVE-2025-54881Mermaid is a JavaScript based diagramming and charting tool …5.3
- CVE-2025-54882Himmelblau is an interoperability suite for Microsoft Azure …7.1
- CVE-2025-54883Vision UI is a collection of enterprise-grade, dependency-fr…9.3
Are you affected by CVE-2025-54878?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
