Impact
Improper input validation in the DHAgreement.CalculateAgreement method of the MTI/A0 two‑pass Diffie‑Hellman implementation allows an attacker to supply a crafted out‑of‑range or small‑order public value. This causes the endpoint to compute an agreed value that the attacker already knows, removing the assurance that the derived key is authentic. The flaw also enables a malicious peer to recover the local static private key modulo small factors of p‑1, and in some groups to recover the full key. The result is a fundamental loss of confidentiality and authentication.
Affected Systems
The vulnerability affects the Legion of the Bouncy Castle Inc. bc‑csharp library in all releases before 2.7.0 on any platform where applications invoke DHAgreement directly for key agreement using MTI/A0. Systems that employ this library for secure communications or cryptographic protocols are potentially impacted.
Risk and Exploitability
The flaw is quantified with a CVSS score of 9.1, indicating high severity. No EPSS score is available, but the vulnerability does not appear in CISA’s KEV catalog. An on‑path attacker or a malicious peer can exploit the flaw by injecting a crafted public key; successful exploitation results in the local party deriving a known shared secret and revealing its static private key in certain configurations. The attack is relatively straightforward for anyone able to influence the peer’s DH public value.
OpenCVE Enrichment