← Back

CVE-2010-0928

nvd nist
Published: Mar 5, 2010Modified: Apr 29, 2026

JSON object

Loading...
4.0
Vector
AV:L/AC:H/Au:N/C:C/I:N/A:N
Exploitability: 1.9 / Impact: 6.9
Source: NVD

Description

OpenSSL 0.9.8i on the Gaisler Research LEON3 SoC on the Xilinx Virtex-II Pro FPGA uses a Fixed Width Exponentiation (FWE) algorithm for certain signature calculations, and does not verify the signature before providing it to a caller, which makes it easier for physically proximate attackers to determine the private key via a modified supply voltage for the microprocessor, related to a "fault-based attack."

Affected (1)

Products: Openssl: Openssl
1 product
Openssl
Configuration A
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Version 0.9.8i
Running on/withPlatform Versions
Gaisler
Leon3 Soc
All versions
Xilinx
Virtex Ii Pro Fpga
All versions

Related CWEs

Timeline

No history available yet.