CVE-2007-3108

Modified
Published: 08 Aug 2007, 01:11
Last modified:07 Aug 2024, 14:05

Vulnerability Summary

Overall Risk (default)
minimal
5/100
CVSS Score
1.2 LOW
v2.0 (nvd)
EPSS Score
0.15% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

08 Aug 2007, 01:11
Published
Vulnerability first disclosed
07 Aug 2024, 14:05
Last Modified
Vulnerability information updated

Description

The BN_from_montgomery function in crypto/bn/bn_mont.c in OpenSSL 0.9.8e and earlier does not properly perform Montgomery multiplication, which might allow local users to conduct a side-channel attack and retrieve RSA private keys.

CVSS Metrics

  • v2.0LOWScore: 1.2AV:L/AC:H/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 0.15% Percentile: 36%

Affected Systems

  • UnknownOpenSSL

    ≤ 0.9.8e

References (46)