Impact
The vulnerability in the IesEngine implementation allows a remote attacker who has captured an IES or ECIES ciphertext to recover its plaintext through a CBC padding‑oracle attack. The engine decrypts the ciphertext and removes the padding before verifying the MAC, which means a padding failure is reported with a different error message than a MAC failure, leaking information about the plaintext. This flaw is a classic information‑exposure weakness (CWE-203).
Affected Systems
Applications using the Bouncy Castle bc-csharp library prior to version 2.7.0 are affected. The flaw only manifests when IesEngine is constructed with a padded block‑cipher mode such as AES in CBC mode with PKCS#7 padding. Stream‑mode IES is not impacted.
Risk and Exploitability
The CVSS score of 8.2 classifies the issue as high severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, but the attack requires only the submission of modified ciphertexts under the same key pair, making it feasible for a remote attacker. The impact could be significant if sensitive data are encrypted with susceptible configurations.
OpenCVE Enrichment