Impact
An unbounded iteration count is read from a supplied PKCS#12 file during load time, allowing an attacker to specify a value near 2^31 for the MAC or PBE parameters. The key derivation process repeats the operation that many times before any MAC or password validation occurs, consuming CPU resources until the system becomes unresponsive. The vulnerability results in service interruption but does not provide direct data exfiltration or code execution.
Affected Systems
Legion of the Bouncy Castle Inc. bc-csharp prior to version 2.7.0 is affected. Both the PKCS#12 keystore loader (Pkcs12Store.Load) and the Pkcs12Utilities.ConvertToDefiniteLength functions lack bounds checking for iteration counts in MacData and shrouded key bags.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate to high severity for denial of service. EPSS data is not available, making the likelihood of exploitation difficult to gauge; however, the lack of a KEV listing suggests it has not yet been leveraged in the wild. An attacker who can supply a crafted PKCS#12 file to an application using bc‑csharp can trigger the CPU‑intensive loop, potentially affecting any system that loads untrusted keystore files.
OpenCVE Enrichment