Impact
A padding oracle exists in the CMS RSA PKCS#1 v1.5 key‑transport unwrap process that allows an attacker who has captured a CMS EnvelopedData message to perform a Bleichenbacher‑style adaptive chosen‑ciphertext attack. By submitting many modified ciphertexts to an application that uses the recipient’s RSA private key, the attacker can distinguish a "bad padding" error from other decryption failures, leading to recovery of the content‑encryption key and thus the plaintext of the original message.
Affected Systems
The vulnerability is present in Legion of the Bouncy Castle Inc. bc‑csharp library, affecting all releases prior to 2.7.0. Consumers of this library that decode CMS EnvelopedData are exposed unless they update to the patched version.
Risk and Exploitability
The CVSS score of 8.2 indicates a high‑severity flaw. No EPSS score is available, but the clear padding oracle and absence of random key injection make exploitation a high‑risk activity. The attack requires that the attacker have a captured message and can send modified ciphertexts to an application that performs CMS decryption, so any service exposing this functionality remotely becomes a target.
OpenCVE Enrichment