CyberRota Analysis
AI-GeneratedThe vulnerability exists in the PKCS#12 key derivation process of the Bouncy Castle library, where an attacker can exploit a zero or negative iteration count in a provided PKCS#12 file or PKCS#8 encrypted private key, leading to a denial of service through excessive CPU consumption. This flaw can cause significant performance degradation, as the derivation loop may run for an extended period, effectively freezing the application. Organizations using affected versions of the Bouncy Castle library should prioritize patching to mitigate the risk of service disruption.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Loop with unreachable exit condition in the PKCS#12 key derivation (Pkcs12ParametersGenerator) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply a PKCS#12 (PFX) file, or a PKCS#8 encrypted private key that uses a PKCS#12 password-based encryption algorithm, to cause a denial of service through CPU exhaustion via an iteration count of zero or below, because the derivation loop ran until its counter equalled the count, so for such a count it wrapped through about 2^32 iterations before the MAC or the password could be checked. A 75-byte PFX file with a negative MacData iteration count kept Pkcs12Store.Load busy for many minutes.