Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vgmm-r7wp-gmv8

Опубликовано: 15 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

The Rambus SafeZone Basic Crypto Module, as used in certain Fujifilm (formerly Fuji Xerox) devices before 2022-03-01 and potentially many other devices, generates RSA keys that can be broken with Fermat's factorization method. This allows efficient calculation of private RSA keys from the public key of a TLS certificate.

The Rambus SafeZone Basic Crypto Module, as used in certain Fujifilm (formerly Fuji Xerox) devices before 2022-03-01 and potentially many other devices, generates RSA keys that can be broken with Fermat's factorization method. This allows efficient calculation of private RSA keys from the public key of a TLS certificate.

EPSS

Процентиль: 66%
0.00523
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-330

Связанные уязвимости

CVSS3: 9.1
nvd
почти 4 года назад

The Rambus SafeZone Basic Crypto Module before 10.4.0, as used in certain Fujifilm (formerly Fuji Xerox) devices before 2022-03-01, Canon imagePROGRAF and imageRUNNER devices through 2022-03-14, and potentially many other devices, generates RSA keys that can be broken with Fermat's factorization method. This allows efficient calculation of private RSA keys from the public key of a TLS certificate.

CVSS3: 9.1
fstec
почти 4 года назад

Уязвимость функции CLS_PK_KeyGenMT() базового криптомодуля Rambus SafeZone, позволяющая нарушителю вычислять закрытые ключи RSA из открытого ключа сертификата TLS

EPSS

Процентиль: 66%
0.00523
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-330