CVE Database · CVE-2007-5502
CVSS v3.1
N/A
EPSS
2.31%
Published
Dec 1, 2007
Modified
Apr 22, 2026
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
The PRNG implementation for the OpenSSL FIPS Object Module 1.1.1 does not perform auto-seeding during the FIPS self-test, which generates random data that is more predictable than expected and makes it easier for attackers to bypass protection mechanisms that rely on the randomness.
Weaknesses (CWE)
Affected Products (1)
References (14)