Impact
A loop in the PKCS#12 key derivation routine of Legion of the Bouncy Castle Inc. bc‑csharp fails to exit when the iteration count is zero or negative, causing the loop to run through the full 32‑bit counter space. This results in extreme CPU usage and a denial of service. The flaw is a classic uncontrolled loop condition. The associated CWE is 835.
Affected Systems
Legion of the Bouncy Castle Inc. bc‑csharp versions prior to 2.7.0.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate severity with substantial impact on availability. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an attacker who can supply a crafted PKCS#12 (PFX) file or a PKCS#8 encrypted private key that uses a PKCS#12 password‑based encryption algorithm. An application that processes such files without validation will execute the derivation loop until the counter wraps around, consuming CPU resources for roughly 2^32 iterations and effectively starving the system.
OpenCVE Enrichment