CVE-2010-0928
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
OpenSSL 0.9.8i on the Gaisler Research LEON3 SoC on the Xilinx Virtex-II Pro FPGA uses a Fixed Width Exponentiation (FWE) algorithm for certain signature calculations, and does not verify the signature before providing it to a caller, which makes it easier for physically proximate attackers to determine the private key via a modified supply voltage for the microprocessor, related to a "fault-based attack."
OpenSSL 0.9.8i en Gaisler Research LEON3 SoC sobre Xilinx Virtex-II Pro FPGA utiliza un algoritmo Fixed Width Exponentiation (FWE) para ciertos calculos de firma, el cual no verifica previamente la firma del cliente, lo que hace que atacantes proximos fisicamente puedan determinar la clave privada a traves de una modificacion del voltaje del microprocesador, relacionado con el ataque "fault-based attack."
CVSS Scores
SSVC
- Decision:-
Timeline
- 2010-03-05 CVE Reserved
- 2010-03-05 CVE Published
- 2023-11-08 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-310: Cryptographic Issues
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://rdist.root.org/2010/03/08/attacking-rsa-exponentiation-with-fault-injection | X_refsource_misc | |
http://www.eecs.umich.edu/~valeria/research/publications/DATE10RSA.pdf | X_refsource_misc | |
http://www.networkworld.com/news/2010/030410-rsa-security-attack.html | X_refsource_misc | |
http://www.osvdb.org/62808 | Vdb Entry | |
http://www.theregister.co.uk/2010/03/04/severe_openssl_vulnerability | X_refsource_misc | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/56750 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Openssl Search vendor "Openssl" | Openssl Search vendor "Openssl" for product "Openssl" | 0.9.8i Search vendor "Openssl" for product "Openssl" and version "0.9.8i" | - |
Affected
| in | Gaisler Search vendor "Gaisler" | Leon3 Soc Search vendor "Gaisler" for product "Leon3 Soc" | * | - |
Safe
|
Openssl Search vendor "Openssl" | Openssl Search vendor "Openssl" for product "Openssl" | 0.9.8i Search vendor "Openssl" for product "Openssl" and version "0.9.8i" | - |
Affected
| in | Xilinx Search vendor "Xilinx" | Virtex-ii Pro Fpga Search vendor "Xilinx" for product "Virtex-ii Pro Fpga" | * | - |
Safe
|