openssl: RSA authentication weakness
Published Mar 5, 2010
4.0
MEDIUMCVSS 2.0
EPSS 0.54%
Description
OpenSSL 0.9.8i on the Gaisler Research LEON3 SoC on the Xilinx Virtex-II Pro FPGA uses a Fixed Width Exponentiation (FWE) algorithm for certain signature calculations, and does not verify the signature before providing it to a caller, which makes it easier for physically proximate attackers to determine the private key via a modified supply voltage for the microprocessor, related to a "fault-based attack."
Affected products
Remediation
Red Hat statement
CVE-2010-0928 describes a fault-based attack on OpenSSL where an attacker has precise control over the target system environment in order to be able to introduce faults through power supply manipulation. The attack is not a viable threat to OpenSSL as used in Red Hat products. The Red Hat Product Security has rated this issue as having low security impact and we do not intend to issue updates to address it.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:L/AC:H/Au:N/C:C/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (10 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.54% (0.00536) | 43.11th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.54% (0.00536) | 40.73th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.09% (0.00094) | 24.30th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.07% (0.00066) | 31.05th | v3 (v2023.03.01) |
| Nov 8, 2023 | 0.07% (0.00066) | 27.60th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.06% (0.00062) | 24.25th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.03% (0.01034) | 41.69th | v2 (v2022.01.01) |
| Sep 10, 2022 | 1.03% (0.01034) | 39.91th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.03% (0.01034) | 37.91th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.03% (0.01034) | 20.32th | v2 (v2022.01.01) |
References (10)
- http://rdist.root.org/2010/03/08/attacking-rsa-exponentiation-with-fault-injection/ x_refsource_MISC
- http://www.eecs.umich.edu/~valeria/research/publications/DATE10RSA.pdf x_refsource_MISC
- http://www.networkworld.com/news/2010/030410-rsa-security-attack.html x_refsource_MISC
- http://www.osvdb.org/62808 vdb-entryx_refsource_OSVDB
- http://www.theregister.co.uk/2010/03/04/severe_openssl_vulnerability/ x_refsource_MISC
- https://access.redhat.com/security/cve/CVE-2010-0928 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=570942 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56750 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2010-0928
- https://www.cve.org/CVERecord?id=CVE-2010-0928
| Link | Providers | Tags |
|---|---|---|
| http://rdist.root.org/2010/03/08/attacking-rsa-exponentiation-with-fault-injection/ | x_refsource_MISC | |
| http://www.eecs.umich.edu/~valeria/research/publications/DATE10RSA.pdf | x_refsource_MISC | |
| http://www.networkworld.com/news/2010/030410-rsa-security-attack.html | x_refsource_MISC | |
| http://www.osvdb.org/62808 | vdb-entryx_refsource_OSVDB | |
| http://www.theregister.co.uk/2010/03/04/severe_openssl_vulnerability/ | x_refsource_MISC | |
| https://access.redhat.com/security/cve/CVE-2010-0928 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=570942 | Issue Tracking | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/56750 | vdb-entryx_refsource_XF | |
| https://nvd.nist.gov/vuln/detail/CVE-2010-0928 | ||
| https://www.cve.org/CVERecord?id=CVE-2010-0928 |
Change history (0)
No recorded changes yet.