Impact
In Bouncy Castle for Java versions prior to 1.86, the legacy PBES1 and PKCS#12 PBE algorithms accepted an iterator count directly from untrusted input without bounding it; this allowed an attacker to set the count to any integer value, potentially triggering an arbitrarily large number of cryptographic operations that drain CPU time and memory before authentication succeeds, thus resulting in denial of service. The flaw originates from a lack of bounds checking in the derived key generation step (CWE-770).
Affected Systems
The vulnerability affects the raw Java Cryptography Architecture provider supplied by Bouncy Castle Inc., specifically the BC-JAVA library for all versions before 1.86 and the BC-LTS-JAVA library for all LTS versions before 2.73.13.
Risk and Exploitability
The vulnerability has a CVSS score of 5.3 and is not listed in the CISA KEV catalog; the EPSS score is not available, indicating a currently unclear exploitation probability. The attack vector is to supply malicious PBES1 or PKCS#12 PBE parameters with an inflated iteration count, causing the target application to perform excessive work during key derivation, which can be executed remotely if the application accepts externally supplied encrypted keys. Because the flaw is a purely resource exhaustion issue, mitigating the risk largely depends on bounding the iteration count or patching the library.
OpenCVE Enrichment