Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sat, 03 Oct 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 02 Oct 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Legion Of The Bouncy Castle Inc.
Legion Of The Bouncy Castle Inc. bc-csharp |
|
| Vendors & Products |
Legion Of The Bouncy Castle Inc.
Legion Of The Bouncy Castle Inc. bc-csharp |
Fri, 02 Oct 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper validation of integrity check value in the AES-CCM implementation (CcmParameters and CcmBlockCipher) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an on-path attacker to modify CCM-encrypted content without detection via an AlgorithmIdentifier whose CCMParameters declare an authentication tag (aes-ICVlen) of zero or another length outside the RFC 5084 set, because CcmParameters accepted any value and CcmBlockCipher validated the tag length only when encrypting, so decryption compared a zero-length or very short tag. Affected paths include ParameterUtilities.GetCipherParameters, used by CmsEnvelopedData and CmsEnvelopedDataParser for EnvelopedData encrypted with AES-CCM, and any caller passing an unchecked tag length to CcmBlockCipher for decryption. | |
| Title | AES-CCM decryption accepts zero or out-of-range tag length, bypassing authentication | |
| Weaknesses | CWE-354 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: bcorg
Published:
Updated: 2026-10-02T18:02:14.715Z
Reserved: 2026-07-16T23:53:17.500Z
Link: CVE-2026-15999
Updated: 2026-10-02T18:02:08.518Z
Status : Awaiting Analysis
Published: 2026-10-02T07:16:36.193
Modified: 2026-10-02T18:17:02.857
Link: CVE-2026-15999
No data.
OpenCVE Enrichment
Updated: 2026-10-02T14:46:20Z