CVE-2026-79954
published 2026-09-18CVE-2026-79954: NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path. The receiver selects the Security Association…
PriorityP354high8.7CVSS 4.0
AVNACLATNPRNUINVCNVIHVANSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.32%
25.5th percentile
NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path. The receiver selects the Security Association used for SDLS processing solely from the SPI field inside the incoming frame, but it does not verify that the selected SA is authorized for the frame's GVCID.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nasa | cryptolib | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
NASA CryptoLib 1.5.0 Receive Path improper authorization
vuldb·2026-09-18·CVSS 8.7
CVE-2026-79954 [HIGH] NASA CryptoLib 1.5.0 Receive Path improper authorization
A vulnerability categorized as very critical has been discovered in NASA CryptoLib 1.5.0. Impacted is an unknown function of the component Receive Path. Such manipulation leads to improper authorization.
This vulnerability is traded as CVE-2026-79954. The attack may be launched remotely. There is no exploit available.
GHSA
NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path.
ghsa_unreviewed·2026-09-18
CVE-2026-79954 [HIGH] CWE-306 NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path.
NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path. The receiver selects the Security Association used for SDLS processing solely from the SPI field inside the incoming frame, but it does not verify that the selected SA is authorized for the frame's GVCID.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-18
Published