Impact
Allocation of resources without limits during password‑based decryption of PKCS#8 private keys allows an attacker to supply a key file with an iteration count near 2^31. The derivation function then consumes excessive CPU, leading to denial of service. The flaw resides in the PbeUtilities.GenerateCipherParameters routine of Bouncy Castle bc‑csharp versions prior to 2.7.0 and affects PBES1, PBES2, PBKDF2, PKCS#12, and CMS password recipient schemes.
Affected Systems
Legion of the Bouncy Castle Inc. publishes the bc‑csharp library for .NET. Versions older than 2.7.0 of bc‑csharp are vulnerable. Applications that use this library to load or process encrypted PKCS#8, PKCS#12, or CMS files may be exploitable. No specific vendor or product beyond the library is listed.
Risk and Exploitability
The CVSS v3.1 score of 7.1 indicates a moderate impact. The EPSS score is not available, and the vulnerability is not in the CISA KEV catalog. Because the attacker must provide an encrypted key file, the attack is likely local or requires the ability to influence the input processed by the application. The lack of input validation on the iteration count presents a straightforward denial‑of‑service vector through CPU exhaustion.
OpenCVE Enrichment