The post NASA Mission Control Security Bug Stayed Hidden For 3 Years appeared on BitcoinEthereumNews.com. Researchers reveal NASA vulnerability that went unfixed for three years. SOPA Images/LightRocket via Getty Images Security vulnerability researchers have exclusively revealed to me that a critical bug remained hidden in the software protecting communications between NASA spacecraft and Earth for an incredible three years. A successful attacker could, but fortunately didn’t, “influence or disrupt spacecraft operations in mission-significant ways,” Stanislav Fort, co-founder and chief scientist at AISLE, the security organization that discovered and responsibly disclosed the vulnerability to NASA, said. Here’s everything you need to know as cybersecurity in space comes under the spotlight. ForbesCISA Warns iPhone And Android Users — Secure Your Smartphone NowBy Davey Winder When NASA Authentication Code Becomes A Space Attack Vector Authentication code is the glue holding many security systems together. Whether you are talking about basic-level two-factor authentication as used to help secure our apps, or the more advanced stuff used to encrypt data within things like Windows BitLocker. When it comes to mission-critical software, such as that developed and used by NASA and crucial for protecting the communications between spacecraft and Earth, you would hope that authentication is both highly advanced and highly secure. Yet a critical flaw in CryptoLib, unearthed, pardon the pun, by AISLE’s autonomous analyzer, was uncovered in the authentication path. Tracked as CVE-2025-59534, it turned out that the vulnerability had stayed hidden in plain sight for three years, between September 2022 and September 2025. “For over 1,100 days,” Fort said, “authentication code meant to secure spacecraft communications contained a command injection vulnerability.”A rapid response by NASA ensured that, upon disclosure, the vulnerability was fixed within four days. “The vulnerability transformed what should be a routine authentication configuration into a weapon,” Fort told me in an exclusive interview, adding that “an attacker who can control either the username or keytab… The post NASA Mission Control Security Bug Stayed Hidden For 3 Years appeared on BitcoinEthereumNews.com. Researchers reveal NASA vulnerability that went unfixed for three years. SOPA Images/LightRocket via Getty Images Security vulnerability researchers have exclusively revealed to me that a critical bug remained hidden in the software protecting communications between NASA spacecraft and Earth for an incredible three years. A successful attacker could, but fortunately didn’t, “influence or disrupt spacecraft operations in mission-significant ways,” Stanislav Fort, co-founder and chief scientist at AISLE, the security organization that discovered and responsibly disclosed the vulnerability to NASA, said. Here’s everything you need to know as cybersecurity in space comes under the spotlight. ForbesCISA Warns iPhone And Android Users — Secure Your Smartphone NowBy Davey Winder When NASA Authentication Code Becomes A Space Attack Vector Authentication code is the glue holding many security systems together. Whether you are talking about basic-level two-factor authentication as used to help secure our apps, or the more advanced stuff used to encrypt data within things like Windows BitLocker. When it comes to mission-critical software, such as that developed and used by NASA and crucial for protecting the communications between spacecraft and Earth, you would hope that authentication is both highly advanced and highly secure. Yet a critical flaw in CryptoLib, unearthed, pardon the pun, by AISLE’s autonomous analyzer, was uncovered in the authentication path. Tracked as CVE-2025-59534, it turned out that the vulnerability had stayed hidden in plain sight for three years, between September 2022 and September 2025. “For over 1,100 days,” Fort said, “authentication code meant to secure spacecraft communications contained a command injection vulnerability.”A rapid response by NASA ensured that, upon disclosure, the vulnerability was fixed within four days. “The vulnerability transformed what should be a routine authentication configuration into a weapon,” Fort told me in an exclusive interview, adding that “an attacker who can control either the username or keytab…

NASA Mission Control Security Bug Stayed Hidden For 3 Years

2025/11/28 22:55

Researchers reveal NASA vulnerability that went unfixed for three years.

SOPA Images/LightRocket via Getty Images

Security vulnerability researchers have exclusively revealed to me that a critical bug remained hidden in the software protecting communications between NASA spacecraft and Earth for an incredible three years. A successful attacker could, but fortunately didn’t, “influence or disrupt spacecraft operations in mission-significant ways,” Stanislav Fort, co-founder and chief scientist at AISLE, the security organization that discovered and responsibly disclosed the vulnerability to NASA, said. Here’s everything you need to know as cybersecurity in space comes under the spotlight.

ForbesCISA Warns iPhone And Android Users — Secure Your Smartphone Now

When NASA Authentication Code Becomes A Space Attack Vector

Authentication code is the glue holding many security systems together. Whether you are talking about basic-level two-factor authentication as used to help secure our apps, or the more advanced stuff used to encrypt data within things like Windows BitLocker.

When it comes to mission-critical software, such as that developed and used by NASA and crucial for protecting the communications between spacecraft and Earth, you would hope that authentication is both highly advanced and highly secure. Yet a critical flaw in CryptoLib, unearthed, pardon the pun, by AISLE’s autonomous analyzer, was uncovered in the authentication path. Tracked as CVE-2025-59534, it turned out that the vulnerability had stayed hidden in plain sight for three years, between September 2022 and September 2025. “For over 1,100 days,” Fort said, “authentication code meant to secure spacecraft communications contained a command injection vulnerability.”A rapid response by NASA ensured that, upon disclosure, the vulnerability was fixed within four days.

“The vulnerability transformed what should be a routine authentication configuration into a weapon,” Fort told me in an exclusive interview, adding that “an attacker who can control either the username or keytab file path configuration values (perhaps through compromised operator credentials or social engineering) can inject arbitrary commands that execute with full system privileges.” If it needs spelling out, when it comes to spacecraft operations, this is particularly dangerous as “that authentication configuration often happens during mission setup or system maintenance, periods when security vigilance might be focused elsewhere.”

Just how dangerous this security vulnerability was can be seen in the potential havoc it could wreak if exploited. Fort told me that, in very practical terms, this could include:

In practical terms, this could enable:

  • Access to classified mission data.
  • Injecting false telemetry data or disrupting communications during critical mission phases.
  • Command and control compromise.
  • Compromising the ground infrastructure that connects mission controllers to vehicles in orbit

ForbesFBI Warns That Hackers Are Posing As Fake Feds — What You Need To Know

What You Need To Know About The NASA CVE-2025-59534 Vulnerability

“Space missions rely on trustworthy cryptography. CryptoLib implements the Space Data Link Security protocol used across NASA missions,” Fort explained, “when that layer fails, spacecraft commands, telemetry, and science data are at stake.” CVE-2025-59534 was that weak point. The vulnerable function built a ‘kinit command string’ from configuration values and executed it via system(). “Shell metacharacters in username or keytab\_file\_path turned configuration into code,” Fort said, “a design choice that made authentication code an execution vector.”

The reason it could stay undiscovered for so long is that “a familiar system() pattern lived in a CAM/keytab login path that teams rarely exercise,” I was told, “while reviews and tests didn’t include adversarial inputs and configuration was implicitly trusted.” This meant that code review, static analysis, and fuzzing didn’t flag it because it lives in configuration-handling code that looks harmless. “The triggering inputs are valid config strings with shell meta characters,” Fort explained, “which fuzzers rarely explore.”

You can read the full technical report here.

A NASA spokesperson provided the following statement: “NASA prioritizes the cybersecurity of its systems to ensure they remain safe, trustworthy, and reliable for visitors. In addition to continuously scanning our systems for vulnerabilities, we also invite the public and security researchers to report any potential problems or misuses of our systems in good faith, through our Vulnerability Disclosure Program. NASA takes prompt action to validate and resolve all third-party reports, identifying and mitigating them appropriately.”

ForbesDo Not Download These Windows Security Updates, Experts Warn

Source: https://www.forbes.com/sites/daveywinder/2025/11/28/nasa-mission-control-security-bug-stayed-hidden-for-3-years/

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Spot XRP ETFs Nears $1B AUM Milestone as Streak of No Outflows Continues

Spot XRP ETFs Nears $1B AUM Milestone as Streak of No Outflows Continues

The post Spot XRP ETFs Nears $1B AUM Milestone as Streak of No Outflows Continues appeared on BitcoinEthereumNews.com. The U.S. Spot XRP ETFs is now near the $1 billion mark of assets under management in less than a month since their launch. This follows from the product maintaining consistent inflows with no single outflow recorded yet. XRP ETFs See Continuous Inflows Since Launch Since its first launch on November 14, spot XRP funds have seen continued inflows. According to data from SoSoValue, the total inflows into these funds have now risen to $881.25 million. The funds attracted $12.84 million of new money yesterday. The daily trading volumes remained stable at $26.74 million. Source: SoSoValue Reaching nearly $1 billion in less than 30 days makes the product among the fastest growing crypto investment products in the United States. Notably, Spot Solana ETFs also accumulated over $600 million since their launch. On the other hand, Bitcoin and Ethereum ETFs are holding about $58 billion and about $13 billion in assets under management respectively. Much of the early growth traces back to the first Canary Capital’s XRP ETF. Its opening on November 13 brought one of the strongest crypto ETF openings to date. It saw more than $59 million in first-day trading volume and $245 million in net inflows. Shortly after Canary’s launch, firms like Grayscale, Bitwise, and Franklin Templeton introduced their own XRP products. Bitwise’s fund also did well on its launch, recording over $105 million in early inflows. Meanwhile, the market is getting ready for yet another addition. 21Shares’ U.S. spot XRP fund also got the green light from the SEC. It will trade under the ticker TOXR on the Cboe BZX Exchange. XRP Products Keep Gaining Momentum in the Market The token’s funds continued to expand this week. REX Shares and Tuttle Capital have launched the T-REX 2X Long XRP Daily Target ETF. This new ETF allows traders…
Share
BitcoinEthereumNews2025/12/05 14:11