Erroneously using an all-zero seed for RSA-OEAP padding instead of the generated random bytes, in Oberon microsystems AG’s Oberon PSA Crypto library in all versions up to 1.5.1, results in deterministic RSA and thus in a loss of confidentiality for guessable messages, recognition of repeated messages, and loss of security proofs.
CVSS
No CVSS.
References
Link | Resource |
---|---|
https://www.oberon.ch/security-advisories/cve-2025-9071/ |
Configurations
No configuration.
History
29 Aug 2025, 10:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-29 10:15
Updated : 2025-08-29 16:24
NVD link : CVE-2025-9071
Mitre link : CVE-2025-9071
CVE.ORG link : CVE-2025-9071
JSON object : View
Products Affected
No product.
CWE
CWE-780
Use of RSA Algorithm without OAEP