Junglewise Threat Intelligence

CVE-2026-79954: NASA CryptoLib authentication downgrade in Telecommand receive

CVE-2026-79954 · Severity: info · Published 2026-09-18

Vendors: Nasa.

Executive brief

NASA CryptoLib is a security library used to protect communications between spacecraft and ground stations using cryptographic protocols. This vulnerability allows an attacker to use security credentials from an unauthorized communication channel to bypass authentication checks, potentially allowing unauthorized telecommands to reach the spacecraft.

Technical details

The vulnerability is an authentication bypass in the Telecommand (TC) receive path of NASA CryptoLib 1.5.0. The receiver selects the Security Association (SA) used for SDLS processing based solely on the SPI (Security Parameter Index) field from the incoming frame, without verifying that the selected SA is authorized for the frame's GVCID (Ground Virtual Channel ID). This allows an attacker to craft frames that reference a valid SA from a different GVCID, bypassing intended access controls. The vulnerability requires network access to the TC receive path. A patch or mitigated version is likely available as this has been formally disclosed with a CVE.

Affected products

  • NASA CryptoLib 1.5.0

Timeline

  • 2026-09-18: disclosed

References