CVE-2010-0928
Severity CVSS v4.0:
Pending analysis
Type:
CWE-310
Cryptographic Issues
Publication date:
05/03/2010
Last modified:
11/04/2025
Description
OpenSSL 0.9.8i on the Gaisler Research LEON3 SoC on the Xilinx Virtex-II Pro FPGA uses a Fixed Width Exponentiation (FWE) algorithm for certain signature calculations, and does not verify the signature before providing it to a caller, which makes it easier for physically proximate attackers to determine the private key via a modified supply voltage for the microprocessor, related to a "fault-based attack."
Impact
Base Score 2.0
4.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:openssl:openssl:0.9.8i:*:*:*:*:*:*:* | ||
| cpe:2.3:h:gaisler:leon3_soc:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:xilinx:virtex-ii_pro_fpga:*:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://rdist.root.org/2010/03/08/attacking-rsa-exponentiation-with-fault-injection/
- http://www.eecs.umich.edu/~valeria/research/publications/DATE10RSA.pdf
- http://www.networkworld.com/news/2010/030410-rsa-security-attack.html
- http://www.osvdb.org/62808
- http://www.theregister.co.uk/2010/03/04/severe_openssl_vulnerability/
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56750
- http://rdist.root.org/2010/03/08/attacking-rsa-exponentiation-with-fault-injection/
- http://www.eecs.umich.edu/~valeria/research/publications/DATE10RSA.pdf
- http://www.networkworld.com/news/2010/030410-rsa-security-attack.html
- http://www.osvdb.org/62808
- http://www.theregister.co.uk/2010/03/04/severe_openssl_vulnerability/
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56750



