4
CVSSv2

CVE-2010-0928

Published: 05/03/2010 Updated: 07/11/2023
CVSS v2 Base Score: 4 | Impact Score: 6.9 | Exploitability Score: 1.9
VMScore: 358
Vector: AV:L/AC:H/Au:N/C:C/I:N/A:N

Vulnerability Summary

OpenSSL 0.9.8i on the Gaisler Research LEON3 SoC on the Xilinx Virtex-II Pro FPGA uses a Fixed Width Exponentiation (FWE) algorithm for certain signature calculations, and does not verify the signature before providing it to a caller, which makes it easier for physically proximate malicious users to determine the private key via a modified supply voltage for the microprocessor, related to a "fault-based attack."

Vulnerable Product Search on Vulmon Subscribe to Product

openssl openssl 0.9.8i