endpointlabs / VulnerableDotNetCore3Project

.Net Core 3.0
0 stars 0 forks source link

CVE-2010-0928 | openssl (CWE-310) #61

Open cbilgin23 opened 2 years ago

cbilgin23 commented 2 years ago

Due Date: 2022-10-11

A low severity vulnerability has been discovered in your project.

Project Name: twrap-go

Scanner Name: trivy

Cwe ID: 310

Cwe Name: Crytographic Issues

Cwe Link: https://cwe.mitre.org/data/definitions/310.html

CVE ID: CVE-2010-0928

Target: nginx:latest (debian 11.5)

Packages:

References:

Tool Description: OpenSSL 0.9.8i on the Gaisler Research LEON3 SoC on the Xilinx Virtex-II Pro FPGA uses a Fixed Width Exponentiation (FWE) algorithm for certain signature calculations, and does not verify the signature before providing it to a caller, which makes it easier for physically proximate attackers to determine the private key via a modified supply voltage for the microprocessor, related to a "fault-based attack."

Custom Description: test

Kondukto Link: http://79.kondukto.local/projects/634fe837a5be8478724352c4/vulns/appsec?page=1&perPage=15&id=in:6358f3d2b8bfc0fbb2c3b959 Deeplink: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0928