The latest CVE Vulnerability List of openssl/fips_object_module

 

Page content

The latest CVE Vulnerability list for openssl/fips_object_module

openssl/fips_object_module Vulnerability Summary

  • Vendor name: openssl
  • Product name: fips_object_module
  • Total vulnerabilities: 1 (as 2023-04-30)

openssl/fips_object_module Vulnerability List

CVE-2007-5502: The PRNG implementation for the OpenSSL FIPS Object Module 1.1.1 does not perform auto-seeding…

Published: 2007-12-01T06:46:00 Last Modified: 2017-07-29T01:33:00

Summary

The PRNG implementation for the OpenSSL FIPS Object Module 1.1.1 does not perform auto-seeding during the FIPS self-test, which generates random data that is more predictable than expected and makes it easier for attackers to bypass protection mechanisms that rely on the randomness.

Common Weakness Enumeration (CWE): CWE-310

Scores

  • Impact Score: 4.9
  • Exploitability Score: 10.0
  • CVSS: 6.4
  • CVSS Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Impact

  • Availability: NONE
  • Confidentiality: PARTIAL
  • Integrity: PARTIAL

References