Description
Missing cryptographic step in the DSTU 7624 CCM mode implementation (KCcmBlockCipher) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can observe encrypted messages of known or chosen content to forge ciphertexts with valid authentication tags, via messages encrypted without associated data. The cause is that the G1 block, which binds the nonce, the message length and the parameter flags into the CBC-MAC, was processed only when associated data was present. Without associated data the tag was a CBC-MAC of the plaintext alone, independent of the nonce. Only applications that use KCcmBlockCipher directly and supply no associated data are affected.
Published: 2026-10-02
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Authentication forgery via forged ciphertext tags
Action: Patch
AI Analysis

Impact

Missing cryptographic logic in the KCcmBlockCipher implementation of the DSTU 7624 CCM mode allows an attacker who can observe encrypted messages of known or chosen content to forge ciphertexts with valid authentication tags. The issue arises because the nonce, message length, and parameter flags are not incorporated into the CBC‑MAC when no associated data is supplied, resulting in a tag that depends only on the plaintext. If an application directly uses this class with empty associated data, an adversary could modify messages or replay them without detection, potentially enabling unauthorized data manipulation or tampering with integrity.

Affected Systems

Legion of the Bouncy Castle Inc. bc‑csharp version prior to 2.7.0 is affected when applications instantiate KCcmBlockCipher directly and pass no associated data. Only those applications that rely on this constructor and omit additional data are vulnerable; higher‑level APIs that always provide associated data are not impacted.

Risk and Exploitability

The CVSS score is 8.7, indicating high severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an application that uses KCcmBlockCipher without associated data and an attacker who can observe or choose ciphertexts. While the attack vector is application‑specific, the impact on confidentiality and integrity is significant if the vulnerability is leveraged.

Generated by OpenCVE AI on October 2, 2026 at 08:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the bc‑csharp library to version 2.7.0 or later, where the CBC‑MAC correctly incorporates the nonce even when no associated data is supplied.
  • Ensure any custom usage of KCcmBlockCipher supplies non‑empty associated data; if empty data is required, add a placeholder byte or use a higher‑level API that enforces this.
  • Audit existing code to identify direct instantiations of KCcmBlockCipher with missing associated data and modify the encryption logic accordingly.

Generated by OpenCVE AI on October 2, 2026 at 08:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 07:15:00 +0000

Type Values Removed Values Added
Description Missing cryptographic step in the DSTU 7624 CCM mode implementation (KCcmBlockCipher) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can observe encrypted messages of known or chosen content to forge ciphertexts with valid authentication tags, via messages encrypted without associated data. The cause is that the G1 block, which binds the nonce, the message length and the parameter flags into the CBC-MAC, was processed only when associated data was present. Without associated data the tag was a CBC-MAC of the plaintext alone, independent of the nonce. Only applications that use KCcmBlockCipher directly and supply no associated data are affected.
Title KCcmBlockCipher (DSTU 7624 CCM) tag not bound to nonce when no associated data is used
Weaknesses CWE-325
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: bcorg

Published:

Updated: 2026-10-02T06:54:23.546Z

Reserved: 2026-07-16T23:53:32.558Z

Link: CVE-2026-16000

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-02T07:16:36.400

Modified: 2026-10-02T14:44:52.247

Link: CVE-2026-16000

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T09:00:18Z

Weaknesses
  • CWE-325

    Missing Cryptographic Step