CVE-2010-0928 describes a fault-based attack vulnerability in OpenSSL 0.9.8i running on the Gaisler Research LEON3 SoC on Xilinx Virtex-II Pro FPGAs. The vulnerability arises from the Fixed Width Exponentiation (FWE) algorithm used for signature calculations, which lacks signature verification before outputting to a caller. This flaw allows physically proximate attackers to determine the private key by manipulating the microprocessor's supply voltage. With a CVSS score of 4.0, this vulnerability has a local attack vector and high attack complexity, leading to a complete compromise of confidentiality. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.9.8iCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:0.9.8i:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:H/Au:N/C:C/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.