RSA and DSA keys generated by CompleteFTP versions 10.0.0-12.0.0 (RSA) and 10.0.0-23.0.4 (DSA) contain predictable patterns of zeros in their moduli, making them vulnerable to factoring attacks. These weak keys were found in SSH hosts using the software, with some instances also appearing in expired certificates from organizations like Yahoo and Verizon, as well as NetApp devices.
| Vendor | Product | Versions |
|---|---|---|
| enterprisedt | completeftp | 10.0.0 - 12.0.0, 10.0.0 - 23.0.4 |