Unrated severityNVD Advisory· Published Dec 1, 2007· Updated Apr 23, 2026
CVE-2007-5502
CVE-2007-5502
Description
The PRNG implementation for the OpenSSL FIPS Object Module 1.1.1 does not perform auto-seeding during the FIPS self-test, which generates random data that is more predictable than expected and makes it easier for attackers to bypass protection mechanisms that rely on the randomness.
Affected products
1- cpe:2.3:a:openssl:fips_object_module:1.1.1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- secunia.com/advisories/27859nvdPatchVendor Advisory
- www.securityfocus.com/bid/26652nvdPatch
- www.kb.cert.org/vuls/id/150249nvdUS Government Resource
- www.openssl.org/news/secadv_20071129.txtnvd
- www.securitytracker.com/idnvd
- www.vupen.com/english/advisories/2007/4044nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/38796nvd
News mentions
0No linked articles in our index yet.