CVE-2025-54878 describes a heap buffer overflow in NASA CryptoLib version 1.4.0 and prior, specifically within the IV setup logic for telecommand frames, affecting the software-only solution for securing cFS communications. This vulnerability, rated 8.6 HIGH (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H), allows an unauthenticated attacker to remotely corrupt heap memory by sending a crafted telecommand frame, potentially leading to denial of service or more severe exploitation. While the FAUCET Risk Score is 82/100, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage. The issue has been patched in version 1.4.0.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.4.1CPE matchmatch criteria | cpe:2.3:a:nasa:cryptolib:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.