Weak RSA Key Generation in OpenSC Affects Multiple Platforms
CVE-2009-1603
7.5HIGH
What is CVE-2009-1603?
The functionality in OpenSC's pkcs11-tool can generate RSA keys with invalid public exponents when used with certain third-party PKCS#11 modules. This flaw potentially enables attackers to decrypt messages that were meant to remain confidential, posing serious security risks for users relying on this cryptographic infrastructure.
