CVE-2010-0928

OpenSSL 0.9.8i - Private Key Exposure via Fault-Based Attack on FWE Algorithm

Title source: llm
STIX 2.1

Description

OpenSSL 0.9.8i on the Gaisler Research LEON3 SoC on the Xilinx Virtex-II Pro FPGA uses a Fixed Width Exponentiation (FWE) algorithm for certain signature calculations, and does not verify the signature before providing it to a caller, which makes it easier for physically proximate attackers to determine the private key via a modified supply voltage for the microprocessor, related to a "fault-based attack."

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/56750
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/62808

Scores

EPSS 0.0009
EPSS Percentile 26.0%

Details

CWE
CWE-310
Status published
Products (1)
openssl/openssl 0.9.8i
Published Mar 05, 2010
Tracked Since Feb 18, 2026