The paranoid side of me wonders if this flaw was accidental or intentional (a la Dual EC DRBG).
In addition, this passage (from an Ars Technica article [0]) seems "interesting":
> The researchers went on to find 15 factorizable keys used for TLS. Strangely, almost all of them contain the string "SCADA" in the common name field. All 15 fingerprinted keys have a characteristic involving their prime numbers that is outside the range of what's produced by the faulty Infineon library, raising the possibility there was a modification of it that hasn't yet been documented.
[0]: https://arstechnica.com/information-technology/2017/10/crypt...