CVE-2026-15999

⚪ Do wiadomości

Nieprawidłowa walidacja wartości integralności w Bouncy Castle pozwala atakującemu na modyfikację zaszyfrowanych danych bez wykrycia.

CVSS
0.0
EPSS
0.2%
Exploit
none
Vendor
Opis źródłowy (NVD)

Improper validation of integrity check value in the AES-CCM implementation (CcmParameters and CcmBlockCipher) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an on-path attacker to modify CCM-encrypted content without detection via an AlgorithmIdentifier whose CCMParameters declare an authentication tag (aes-ICVlen) of zero or another length outside the RFC 5084 set, because CcmParameters accepted any value and CcmBlockCipher validated the tag length only when encrypting, so decryption compared a zero-length or very short tag. Affected paths include ParameterUtilities.GetCipherParameters, used by CmsEnvelopedData and CmsEnvelopedDataParser for EnvelopedData encrypted with AES-CCM, and any caller passing an unchecked tag length to CcmBlockCipher for decryption.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS0.0
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.2%
Opublikowano (NVD)2026-10-02 07:16:36 UTC
Ostatnia modyfikacja (NVD)2026-10-02 18:17:02 UTC
Referencje