Impact
A broken or risky cryptographic algorithm is used in the Legion of the Bouncy Castle Inc. BC-Java bcprov library. The GOSTCTR implementation fails to process more than 255 blocks correctly, which can undermine the security of data encrypted with this algorithm. The weakness is identified as a cryptographic algorithm weakness, allowing an adversary to potentially compromise confidentiality of data.
Affected Systems
Products affected are BC-Java bcprov from version 1.59 up to but excluding 1.84. Organizations using these library versions must review deployment of the GOSTCTR cipher.
Risk and Exploitability
The CVSS score is 9.3, indicating a critical severity. There is no EPSS score available, and the vulnerability is not listed in the CISA KEV catalog. The exact attack vector is not described in the CVE data, but given the nature of the flaw it is inferred that an attacker could exploit the weak encryption to decrypt or forge data if the library is used for cryptographic operations.
OpenCVE Enrichment