CyberRota Analysis
AI-GeneratedImproper certificate validation in the Bouncy Castle library allows attackers controlling a name-constrained intermediate CA to bypass PKIX path validation, potentially leading to the acceptance of malicious certificates. This vulnerability could enable unauthorized access or impersonation, making it critical for organizations using affected versions of the library to prioritize updates to version 2.7.0 or later. Security teams, particularly those managing PKI systems and certificate validation processes, should address this issue promptly to mitigate risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Improper certificate validation in the directoryName name-constraint check (PkixNameConstraintValidator.WithinDNSubtree) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who controls, or can have certificates issued by, a name-constrained intermediate CA to get certificates accepted by PKIX path validation whose subject distinguished name, or a directoryName subjectAltName, lies outside the CA's permitted subtrees, via a name that places other RDNs ahead of a copy of the permitted RDN sequence, because the check looks for the constraint's first RDN anywhere in the name and compares the remaining RDNs from that position, instead of requiring the constraint to be an initial prefix of the name as RFC 5280 sections 4.2.1.10 and 7.1 require.