Impact
Missing cryptographic logic in the KCcmBlockCipher implementation of the DSTU 7624 CCM mode allows an attacker who can observe encrypted messages of known or chosen content to forge ciphertexts with valid authentication tags. The issue arises because the nonce, message length, and parameter flags are not incorporated into the CBC‑MAC when no associated data is supplied, resulting in a tag that depends only on the plaintext. If an application directly uses this class with empty associated data, an adversary could modify messages or replay them without detection, potentially enabling unauthorized data manipulation or tampering with integrity.
Affected Systems
Legion of the Bouncy Castle Inc. bc‑csharp version prior to 2.7.0 is affected when applications instantiate KCcmBlockCipher directly and pass no associated data. Only those applications that rely on this constructor and omit additional data are vulnerable; higher‑level APIs that always provide associated data are not impacted.
Risk and Exploitability
The CVSS score is 8.7, indicating high severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an application that uses KCcmBlockCipher without associated data and an attacker who can observe or choose ciphertexts. While the attack vector is application‑specific, the impact on confidentiality and integrity is significant if the vulnerability is leveraged.
OpenCVE Enrichment