Impact
Improper certificate validation during directoryName name‑constraint checks in Bouncy Castle bc‑csharp allows an attacker who controls a name‑constrained intermediate CA to acquire certificates that are accepted by PKIX path validation even though their distinguished name or directoryName subjectAltName lies outside the CA’s permitted subtrees. The flaw originates in the validator that searches for the constraint’s first RDN anywhere within the certificate’s distinguished name and compares the remaining RDNs from that position, instead of requiring the constraint to be an initial prefix as defined by RFC 5280.
Affected Systems
The vulnerability affects the Bouncy Castle bc‑csharp library supplied by the Legion of the Bouncy Castle Inc. for all releases prior to version 2.7.0. Any system using these library versions for certificate path validation is susceptible.
Risk and Exploitability
With a CVSS score of 8.2 the vulnerability is rated high severity. Exploitation requires the attacker to control certificate issuance or to have a name‑constrained intermediate CA available; once a forged certificate chain is forged, it can be trusted by any application using the affected library, enabling impersonation or man‑in‑the‑middle attacks. The EPSS score is not available and the issue is not listed in CISA’s KEV catalog, but the risk remains substantial in environments that rely on Bouncy Castle for TLS or certificate validation.
OpenCVE Enrichment