SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2016-1000346

In the Bouncy Castle JCE Provider version 1.55 and earlier the other party DH public key is not fully validated.

LOW 3.7EPSS 2.30%

Does this matter?

Lower severity and a low EPSS score (2.30%). Track it; it rarely justifies an emergency change on its own.

Description

In the Bouncy Castle JCE Provider version 1.55 and earlier the other party DH public key is not fully validated. This can cause issues as invalid keys can be used to reveal details about the other party's private key where static Diffie-Hellman is in use. As of release 1.56 the key parameters are checked on agreement calculation.

CVSS 3.0
3.7 LOWCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
2.30% probability · 82th percentile
CISA KEV
Not listed
Weakness
CWE-320
Affected
bouncycastle/bc-java · debian/debian linux
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.