CVE-2025-9071: Oberon Microsystems AG Oberon Psa Crypto
Low severity, CVSS 2.3. EPSS: 0.2% chance of exploitation in the next 30 days.
Erroneously using an all-zero seed for RSA-OEAP padding instead of the generated random bytes, in Oberon microsystems AG’s Oberon PSA Crypto library in all versions up to 1.5.1, results in deterministic RSA and thus in a loss of confidentiality for guessable messages, recognition of repeated messages, and loss of security proofs.
Affected products
- Oberon Microsystems AG Oberon Psa Crypto: from 1.0.0, up to and including 1.5.1
Published 2025-08-29. Last modified 2026-06-17.