Description
Erroneously using an all-zero seed for RSA-OEAP padding instead of the generated random bytes, in Oberon microsystems AG’s Oberon PSA Crypto library in all versions up to 1.5.1, results in deterministic RSA and thus in a loss of confidentiality for guessable messages, recognition of repeated messages, and loss of security proofs.
Problem types
CWE-780 Use of RSA Algorithm without OEAP
Product status
1.0.0
Credits
Nordic Semiconductor ASA
References
www.oberon.ch/security-advisories/cve-2025-9071/