### [CVE-2010-0928](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0928) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description OpenSSL 0.9.8i on the Gaisler Research LEON3 SoC on the Xilinx Virtex-II Pro FPGA uses a Fixed Width Exponentiation (FWE) algorithm for certain signature calculations, and does not verify the signature before providing it to a caller, which makes it easier for physically proximate attackers to determine the private key via a modified supply voltage for the microprocessor, related to a "fault-based attack." ### POC #### Reference - http://www.eecs.umich.edu/%7Evaleria/research/publications/DATE10RSA.pdf - http://www.theregister.co.uk/2010/03/04/severe_openssl_vulnerability/ #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/GrigGM/05-virt-04-docker-hw - https://github.com/PajakAlexandre/wik-dps-tp02 - https://github.com/cdupuis/image-api - https://github.com/chnzzh/OpenSSL-CVE-lib - https://github.com/fokypoky/places-list - https://github.com/garethr/findcve - https://github.com/garethr/snykout - https://github.com/jasona7/ChatCVE