CVE-2008-0166
OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that generates predictable numbers, which makes it easier for remote attackers to conduct brute force guessing attacks against cryptographic keys.
- Affected products
- Openssl
- Openssl
- ≤ 0.9.8g
- Fix
- Available
- CVSS 2.0
- 7.8 HIGH
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 70.7% (99th percentile)
- Weakness
- CWE-338
- NVD status
- Modified
- Published
- 2008-05-13
CVE-2008-0166 at NVD
10 known exploits for CVE-2008-0166
Proof-of-concept code and exploit modules indexed by Sploitus
metasploitable-vulnerability-mapping-with-nmap
pentest-metasploit
Exploit for Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Openssl
Exploit for Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Openssl
Exploit for Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Openssl
Exploit for Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Openssl
Exploit for Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Openssl
OpenSSL 0.9.8c-1 < 0.9.8g-9 (Debian and Derivatives) - Predictable PRNG Brute Force SSH
OpenSSL 0.9.8c-1 < 0.9.8g-9 (Debian and Derivatives) - Predictable PRNG Brute Force SSH (Ruby)
OpenSSL 0.9.8c-1 < 0.9.8g-9 (Debian and Derivatives) - Predictable PRNG Brute Force SSH