CyberRota Analysis
AI-GeneratedThe vulnerability allows remote attackers to exploit the IesEngine in Legion of the Bouncy Castle Inc. bc-csharp versions prior to 2.7.0 by observing a single encrypted message with known plaintext, enabling them to forge shorter authentic messages through crafted ciphertext and MAC tags. The exposure of the message authentication key via the encryption keystream significantly compromises message integrity, making it critical for organizations using this library to prioritize immediate updates to mitigate potential exploitation. Users of affected versions should implement the latest patches to secure their applications against this high-severity threat.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Exposure of the message authentication key through the encryption keystream in the stream mode of IesEngine (an IesEngine constructed without a block cipher) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote attacker who has observed one encrypted message with known plaintext to forge shorter messages of their choosing that the recipient accepts as authentic, via a crafted ciphertext and MAC tag, because the MAC key was taken from the key derivation output directly after a keystream as long as the message, while the derivation input depends only on the static key pair and fixed parameters. The keystream revealed by that one message therefore contains the MAC key for every sufficiently shorter message.