BlackTreeCVE Intelligence
← Back to the CVE catalogue
Full vulnerability report · 2019
CVE-2019-1551High confidence

rsaz_512_sqr overflow bug on x86_64

OpenSSL · OpenSSL

5.3MediumCVSS 3.1
Recommended action
Scheduled

Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.

Patch available
R
Operational reassessment

Published severity in operational context

Open reassessment dashboard →
Published severityMediumOperational priority:High, raised one band.upgradedsince 6 Oct 2026

Evidence used

  • No CISA KEV confirmation is currently recorded.
  • The selected CVSS metric records a network-reachable, unauthenticated path with no user interaction.
  • EPSS is 14.30% for the current model date.

Compensating controls

  • Validate the affected product branch and deploy the verified fixed release.
  • Restrict the affected network interface to trusted sources where business-safe.
  • Monitor vendor guidance and exploitation sources for a material change.

Verification

  1. Confirm that the asset runs OpenSSL OpenSSL and falls inside the recorded affected range.
  2. Verify the installed build against the product-specific fixed version after deployment.
  3. Validate exposure, authentication requirements and compensating controls in the actual environment.
  4. Reopen this reassessment when CVSS, KEV, EPSS, exploit evidence or remediation changes.
Mitigation target: Within 30 daysRemediation target: Within 180 days

This automated reassessment organises public evidence. It does not know asset exposure, business impact or control effectiveness and does not replace CVSS or a human risk decision.

Distribution package intelligence

Release-specific package status

Alpine, Debian findings are scoped to the named distribution, release and source package. An absent finding does not mean a package is unaffected.

7 package states
Repository candidate not checked

A published vendor fix does not prove that a matching update is enabled and installable on a particular asset. Confirm the local package candidate before scheduling remediation.

Distribution releaseSource packageVendor stateFixed versionEvidence
Alpine v3.23v3.23 · mainopensslVendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.1.1.1d-r3Alpine Security Database ↗Source updated 3 Oct 2026
Alpine v3.22v3.22 · mainopensslVendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.1.1.1d-r3Alpine Security Database ↗Source updated 3 Oct 2026
Alpine v3.21v3.21 · mainopensslVendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.1.1.1d-r3Alpine Security Database ↗Source updated 3 Oct 2026
Debian trixietrixie · sourceopensslVendor fix publishedDebian records a fixed source-package version for this release.1.1.1e-1Debian Security Tracker ↗Source updated 6 Oct 2026
Debian bookwormbookworm · sourceopensslVendor fix publishedDebian records a fixed source-package version for this release.1.1.1e-1Debian Security Tracker ↗Source updated 6 Oct 2026
Debian forkyforky · sourceopensslVendor fix publishedDebian records a fixed source-package version for this release.1.1.1e-1Debian Security Tracker ↗Source updated 6 Oct 2026
Debian sidsid · sourceopensslVendor fix publishedDebian records a fixed source-package version for this release.1.1.1e-1Debian Security Tracker ↗Source updated 6 Oct 2026
Direct vendor intelligence

Authoritative vendor CSAF and VEX advisories

Structured product status and remediation from the issuing vendor. Product-state explanations are always visible; large lists can be searched or downloaded.

0 current · 1 archived
CVE-2019-1551 · CSAF 2.0 · revision 3 · finalRed Hat Product Securityopenssl: Integer overflow in RSAZ modular exponentiation on x86_64No longer in the provider’s current catalogue
10 known affected

The vendor explicitly identifies these products as affected by this CVE.

  • openssl as a component of Red Hat Enterprise Linux 7
  • openssl-devel as a component of Red Hat Enterprise Linux 7
  • openssl-libs as a component of Red Hat Enterprise Linux 7
  • openssl-perl as a component of Red Hat Enterprise Linux 7
  • openssl-static as a component of Red Hat Enterprise Linux 7
  • openssl.src as a component of Red Hat Enterprise Linux 7
  • compat-openssl10 as a component of Red Hat Enterprise Linux 8
  • compat-openssl10.src as a component of Red Hat Enterprise Linux 8
  • openssl.src as a component of Red Hat JBoss Enterprise Application Platform 6
  • openssl.src as a component of Red Hat JBoss Enterprise Web Server 2
Summary
An integer overflow was found in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. As per upstream: * No EC algorithms are affected. * Attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a result of this defect would be very difficult to perform and are not believed likely. * Attacks against DH512 are considered just feasible. However, for an attack the target would have to re-use the DH512 private key, which is not recommended anyway. * Also applications directly using the low level API BN_mod_exp may be affected if they use BN_FLG_CONSTTIME
Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
Optional official sources

National CERT insights
?CERT means Computer Emergency Response Team; CSIRT is the closely related term Computer Security Incident Response Team.

Choose official national sources for this report. Each advisory shows its original language. Your selection is remembered on this device and included in shared links.

Official European source

ENISA European Vulnerability Database

Official EUVD identifiers, advisory evidence and known-exploited context. Missing fields are not treated as evidence of low risk.

1 current
ENISA EUVD identifier

EUVD-2019-10108

No EUVD known-exploited evidence

ENISA has published the identifier mapping but no EUVD description has been stored yet.

EUVD state
Present in the current official mapping
Known exploitation
Not present in the current ENISA EUVD known-exploited dataset. This is not proof of no exploitation.
ENISA score
Not supplied in the stored EUVD record
Advisory evidence
No linked advisory details stored yet
Recommended actionScheduled

Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.

Patch available
01

What, why and how

There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH512 are considered just feasible. However, for an attack the target would have to re-use the DH512 private key, which is not recommended anyway. Also applications directly using the low level API BN_mod_exp may be affected if they use BN_FLG_CONSTTIME. Fixed in OpenSSL 1.1.1e (Affected 1.1.1-1.1.1d). Fixed in OpenSSL 1.0.2u (Affected 1.0.2-1.0.2t).

What

There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH512 are considered just feasible. However, for an attack the target would have to re-use the DH512 private key, which is not recommended anyway. Also applications directly using the low level API BN_mod_exp may be affected if they use BN_FLG_CONSTTIME. Fixed in OpenSSL 1.1.1e (Affected 1.1.1-1.1.1d). Fixed in OpenSSL 1.0.2u (Affected 1.0.2-1.0.2t).

Why

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

How

An attacker operating through a network path may attempt exploitation without authentication or user interaction. If successful, the issue may cause the confidentiality, integrity or availability impact described by the vendor.

What

There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH512 are considered just feasible. However, for an attack the target would have to re-use the DH512 private key, which is not recommended anyway. Also applications directly using the low level API BN_mod_exp may be affected if they use BN_FLG_CONSTTIME. Fixed in OpenSSL 1.1.1e (Affected 1.1.1-1.1.1d). Fixed in OpenSSL 1.0.2u (Affected 1.0.2-1.0.2t).

Why

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

How

An attacker operating through a network path may attempt exploitation without authentication or user interaction. If successful, the issue may cause the confidentiality, integrity or availability impact described by the vendor.

02

Exploit reality and attack path

CVSS severity, EPSS forecast probability, public exploit material and CISA-confirmed exploitation are separate signals.

Observed exploitation
?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.
No confirmed evidence

No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.

Public PoC / exploit material
?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.
None recorded

No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.

Likely attack path
a network path → Integer Overflow or Wraparound → cause the confidentiality, integrity or availability impact described by the vendor
Attack surface
Network
Privileges required
None: unauthenticated exploitation is possible
User interaction
None
Attack complexity
Low: no specialised conditions are recorded
Security boundary
Unchanged: impact remains within the vulnerable component's security authority
Weakness
?CWE means Common Weakness Enumeration: a standard category for the underlying weakness.
CWE-190 ↗

CWE-190: Integer Overflow or Wraparound. The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

CVSS vector
?CVSS means Common Vulnerability Scoring System. The vector records the metric values used to calculate technical severity.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Common Vulnerability Scoring System 3.1: the compact vector below is decoded into plain language.

AVNetworkAttack vector: The vulnerable component can be reached over a network.ACLowAttack complexity: No specialised conditions are required beyond attacker-controlled input.PRNonePrivileges required: The attacker does not need an account or existing privileges.UINoneUser interaction: No action by another user is required.SUnchangedScope: The security impact remains within the vulnerable component's authority.CLowConfidentiality impact: A successful attack can cause a limited loss.INoneIntegrity impact: No direct loss is represented by this metric.ANoneAvailability impact: No direct loss is represented by this metric.
Post-exploitation / living off the land
No specific living-off-the-land technique is confirmed in the structured sources. Monitor normal administration tools for activity inconsistent with the affected service's baseline.
NetworkUnauthenticatedCWE-190
A

Official authority intelligence

Only matched European and national findings are included. Language selectors and unavailable sources are omitted.

BSI · German · WID-SEC-2023-1761OpenSSL: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen

Ein entfernter, anonymer Angreifer kann eine Schwachstelle in OpenSSL ausnutzen, um Sicherheitsvorkehrungen zu umgehen.

Official advisory ↗
CERT-FR · French · CERTFR-2026-AVI-0199Multiples vulnérabilités dans les produits VMware

com.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37024 Référence CVE CVE-2016-9843 https://www.cve.org/CVERecord?id=CVE-2016-9843 Référence CVE CVE-2017-15873 https://www.cve.org/CVERecord?id=CVE-2017-15873 Référence CVE CVE-2017-15874 https://www.cve.org/CVERecord?id=CVE-2017-15874 Référence CVE CVE-2017-16544 https://www.cve.org/CVERecord?id=CVE-2017-16544 Référence CVE CVE-2018-1000500 https://www.cve.org/CVERecord?id=CVE-2018-1000500 Référence CVE CVE-2018-1000517 https://www.cve.org/CVERecord?id=CVE-2018-1000517 Référence CVE CVE-2018-20679 https://www.cve.org/CVERecord?id=CVE-2018-20679 Référence CVE CVE-2019-1551 https://www.cve.org/CVERecord?id=CVE-2019-1551 Référence CVE CVE-2019-5435 https://www.cve.org/CVERecord?id=CVE-2019-5435 Référence CVE CVE-2019-5443 https://www.cve.org/CVERecord?id=CVE-2019-5443 Référence CVE CVE-2019-5481 https://www.cve.org/CVERecord?id=CVE-2019-5481 Référence CVE CVE-2019-5482 https://www.cve.org/CVERecord?id=CVE-2019-5482 Référence CVE CVE-2019-5747 https://www.cve.org/CVERecord?id=CVE-2019-5747 Référence CVE CVE-2020-10750 https://www.cve.org/CVERecord?id=CVE-2020-10750 Référence CVE CVE-2020-1967 https://www.cve.org/CVERecord?id=CVE-2020-1967 Référence CVE CVE-2020-1971 https://www.cve.org/CVERecord?id=CVE-2020-1971

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0262Multiples vulnérabilités dans les produits IBM

on). Documentation Bulletin de sécurité IBM 7144911 du 25 mars 2024 https://www.ibm.com/support/pages/node/7144911 Bulletin de sécurité IBM 7145262 du 26 mars 2024 https://www.ibm.com/support/pages/node/7145262 Bulletin de sécurité IBM 7145265 du 26 mars 2024 https://www.ibm.com/support/pages/node/7145265 Bulletin de sécurité IBM 7145367 du 27 mars 2024 https://www.ibm.com/support/pages/node/7145367 Référence CVE CVE-2018-1000632 https://www.cve.org/CVERecord?id=CVE-2018-1000632 Référence CVE CVE-2018-17196 https://www.cve.org/CVERecord?id=CVE-2018-17196 Référence CVE CVE-2019-1547 https://www.cve.org/CVERecord?id=CVE-2019-1547 Référence CVE CVE-2019-1551 https://www.cve.org/CVERecord?id=CVE-2019-1551 Référence CVE CVE-2019-1563 https://www.cve.org/CVERecord?id=CVE-2019-1563 Référence CVE CVE-2020-10683 https://www.cve.org/CVERecord?id=CVE-2020-10683 Référence CVE CVE-2020-10735 https://www.cve.org/CVERecord?id=CVE-2020-10735 Référence CVE CVE-2020-1968 https://www.cve.org/CVERecord?id=CVE-2020-1968 Référence CVE CVE-2020-25659 https://www.cve.org/CVERecord?id=CVE-2020-25659 Référence CVE CVE-2020-27783 https://www.cve.org/CVERecord?id=CVE-2020-27783 Référence CVE CVE-2020-28493 https://www.cve.org/CVERecord?id=CVE-2020-28493 Référence CVE CVE-2020-36242 https://www.cve.org/CVERecord?id=CVE-2

Official advisory ↗
CERT-FR · French · CERTFR-2023-AVI-0051Multiples vulnérabilités dans les produits Juniper

rg/CVERecord?id=CVE-2007-6755 Référence CVE CVE-2016-4658 https://www.cve.org/CVERecord?id=CVE-2016-4658 Référence CVE CVE-2016-8625 https://www.cve.org/CVERecord?id=CVE-2016-8625 Référence CVE CVE-2016-8743 https://www.cve.org/CVERecord?id=CVE-2016-8743 Référence CVE CVE-2017-12613 https://www.cve.org/CVERecord?id=CVE-2017-12613 Référence CVE CVE-2018-25032 https://www.cve.org/CVERecord?id=CVE-2018-25032 Référence CVE CVE-2018-8046 https://www.cve.org/CVERecord?id=CVE-2018-8046 Référence CVE CVE-2019-11287 https://www.cve.org/CVERecord?id=CVE-2019-11287 Référence CVE CVE-2019-1543 https://www.cve.org/CVERecord?id=CVE-2019-1543 Référence CVE CVE-2019-1551 https://www.cve.org/CVERecord?id=CVE-2019-1551 Référence CVE CVE-2019-20934 https://www.cve.org/CVERecord?id=CVE-2019-20934 Référence CVE CVE-2020-0465 https://www.cve.org/CVERecord?id=CVE-2020-0465 Référence CVE CVE-2020-0466 https://www.cve.org/CVERecord?id=CVE-2020-0466 Référence CVE CVE-2020-0543 https://www.cve.org/CVERecord?id=CVE-2020-0543 Référence CVE CVE-2020-0548 https://www.cve.org/CVERecord?id=CVE-2020-0548 Référence CVE CVE-2020-0549 https://www.cve.org/CVERecord?id=CVE-2020-0549 Référence CVE CVE-2020-11668 https://www.cve.org/CVERecord?id=CVE-2020-11668 Référence CVE CVE-2020-12362 https://www.cve.org/CVERecord?id=CVE-2020-12

Official advisory ↗
CERT-FR · French · CERTFR-2022-AVI-916Multiples vulnérabilités dans les produits Juniper

Record?id=CVE-2017-5929 Référence CVE CVE-2018-10689 https://www.cve.org/CVERecord?id=CVE-2018-10689 Référence CVE CVE-2018-20532 https://www.cve.org/CVERecord?id=CVE-2018-20532 Référence CVE CVE-2018-20533 https://www.cve.org/CVERecord?id=CVE-2018-20533 Référence CVE CVE-2018-20534 https://www.cve.org/CVERecord?id=CVE-2018-20534 Référence CVE CVE-2018-25032 https://www.cve.org/CVERecord?id=CVE-2018-25032 Référence CVE CVE-2019-0205 https://www.cve.org/CVERecord?id=CVE-2019-0205 Référence CVE CVE-2019-12735 https://www.cve.org/CVERecord?id=CVE-2019-12735 Référence CVE CVE-2019-1543 https://www.cve.org/CVERecord?id=CVE-2019-1543 Référence CVE CVE-2019-1551 https://www.cve.org/CVERecord?id=CVE-2019-1551 Référence CVE CVE-2019-18282 https://www.cve.org/CVERecord?id=CVE-2019-18282 Référence CVE CVE-2019-19532 https://www.cve.org/CVERecord?id=CVE-2019-19532 Référence CVE CVE-2019-20811 https://www.cve.org/CVERecord?id=CVE-2019-20811 Référence CVE CVE-2019-20934 https://www.cve.org/CVERecord?id=CVE-2019-20934 Référence CVE CVE-2019-2435 https://www.cve.org/CVERecord?id=CVE-2019-2435 Référence CVE CVE-2019-2684 https://www.cve.org/CVERecord?id=CVE-2019-2684 Référence CVE CVE-2019-9518 https://www.cve.org/CVERecord?id=CVE-2019-9518 Référence CVE CVE-2020-0427 https://www.cve.org/CVERecord?id=CVE-2020

Official advisory ↗
CERT-FR · French · CERTFR-2021-AVI-430Multiples vulnérabilités dans Tenable LCE

De multiples vulnérabilités ont été découvertes dans Tenable LCE. Elles permettent à un attaquant de provoquer une exécution de code arbitraire, un déni de service à distance et un contournement de la politique de sécurité.

Official advisory ↗
CERT-FR · French · CERTFR-2020-AVI-840Multiples vulnérabilités dans Tenable Tenable.sc

De multiples vulnérabilités ont été découvertes dans Tenable Tenable.sc. Certaines d'entre elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur, une exécution de code arbitraire à distance et un déni de service à distance.

Official advisory ↗
CERT-FR · French · CERTFR-2020-AVI-691Multiples vulnérabilités dans les produits Juniper

g/CVERecord?id=CVE-2018-20217 Référence CVE CVE-2018-20843 https://www.cve.org/CVERecord?id=CVE-2018-20843 Référence CVE CVE-2018-5729 https://www.cve.org/CVERecord?id=CVE-2018-5729 Référence CVE CVE-2018-5730 https://www.cve.org/CVERecord?id=CVE-2018-5730 Référence CVE CVE-2019-13734 https://www.cve.org/CVERecord?id=CVE-2019-13734 Référence CVE CVE-2019-14846 https://www.cve.org/CVERecord?id=CVE-2019-14846 Référence CVE CVE-2019-1543 https://www.cve.org/CVERecord?id=CVE-2019-1543 Référence CVE CVE-2019-1547 https://www.cve.org/CVERecord?id=CVE-2019-1547 Référence CVE CVE-2019-1549 https://www.cve.org/CVERecord?id=CVE-2019-1549 Référence CVE CVE-2019-1551 https://www.cve.org/CVERecord?id=CVE-2019-1551 Référence CVE CVE-2019-1552 https://www.cve.org/CVERecord?id=CVE-2019-1552 Référence CVE CVE-2019-1559 https://www.cve.org/CVERecord?id=CVE-2019-1559 Référence CVE CVE-2019-1563 https://www.cve.org/CVERecord?id=CVE-2019-1563 Référence CVE CVE-2019-15903 https://www.cve.org/CVERecord?id=CVE-2019-15903 Référence CVE CVE-2020-1747 https://www.cve.org/CVERecord?id=CVE-2020-1747 Référence CVE CVE-2020-1967 https://www.cve.org/CVERecord?id=CVE-2020-1967 Référence CVE CVE-2020-2754 https://www.cve.org/CVERecord?id=CVE-2020-2754 Référence CVE CVE-2020-2755 https://www.cve.org/CVERecord?id=CVE-2020-2755

Official advisory ↗
CERT-FR · French · CERTFR-2020-AVI-435Multiples vulnérabilités dans Oracle MySQL

Résumé De multiples vulnérabilités ont été découvertes dans Oracle MySQL. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à l'intégrité des données et une atteinte à la confidentialité des données. Solution Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation). Documentation Bulletin de sécurité détaillé Oracle cpujul2020 du 14 juillet 2020 https://www.oracle.com/security-alerts/cpujul2020verbose.html#MSQL Bulletin de sécurité Oracle cpujul2020 du 14 juillet 2020 https://www.oracle.com/security-alerts/cpujul2020.html Référence CVE CVE-2019-1551 https://www.cve.org/CVERecord?id=CVE-2019-1551 Référence CVE CVE-2020-14539 https://www.cve.org/CVERecord?id=CVE-2020-14539 Référence CVE CVE-2020-14540 https://www.cve.org/CVERecord?id=CVE-2020-14540 Référence CVE CVE-2020-14547 https://www.cve.org/CVERecord?id=CVE-2020-14547 Référence CVE CVE-2020-14550 https://www.cve.org/CVERecord?id=CVE-2020-14550 Référence CVE CVE-2020-14553 https://www.cve.org/CVERecord?id=CVE-2020-14553 Référence CVE CVE-2020-14559 https://www.cve.org/CVERecord?id=CVE-2020-14559 Référence CVE CVE-2020-14567 https://www.cve.org/CVERecord?id=CVE-2020-14567 Référence CVE CVE-2020-14568 https://www.cve.org/CVERecord?id=C

Official advisory ↗
CERT-FR · French · CERTFR-2020-AVI-420Multiples vulnérabilités dans les produits Juniper

d?id=CVE-2019-11105 Référence CVE CVE-2019-11106 https://www.cve.org/CVERecord?id=CVE-2019-11106 Référence CVE CVE-2019-11107 https://www.cve.org/CVERecord?id=CVE-2019-11107 Référence CVE CVE-2019-11108 https://www.cve.org/CVERecord?id=CVE-2019-11108 Référence CVE CVE-2019-11109 https://www.cve.org/CVERecord?id=CVE-2019-11109 Référence CVE CVE-2019-11110 https://www.cve.org/CVERecord?id=CVE-2019-11110 Référence CVE CVE-2019-11131 https://www.cve.org/CVERecord?id=CVE-2019-11131 Référence CVE CVE-2019-11132 https://www.cve.org/CVERecord?id=CVE-2019-11132 Référence CVE CVE-2019-11147 https://www.cve.org/CVERecord?id=CVE-2019-11147 Référence CVE CVE-2019-1551 https://www.cve.org/CVERecord?id=CVE-2019-1551 Référence CVE CVE-2019-3855 https://www.cve.org/CVERecord?id=CVE-2019-3855 Référence CVE CVE-2019-3856 https://www.cve.org/CVERecord?id=CVE-2019-3856 Référence CVE CVE-2019-3857 https://www.cve.org/CVERecord?id=CVE-2019-3857 Référence CVE CVE-2019-3862 https://www.cve.org/CVERecord?id=CVE-2019-3862 Référence CVE CVE-2019-3863 https://www.cve.org/CVERecord?id=CVE-2019-3863 Référence CVE CVE-2020-1640 https://www.cve.org/CVERecord?id=CVE-2020-1640 Référence CVE CVE-2020-1641 https://www.cve.org/CVERecord?id=CVE-2020-1641 Référence CVE CVE-2020-1643 https://www.cve.org/CVERecord?id=CVE-2020-1643 Ré

Official advisory ↗
CERT-FR · French · CERTFR-2020-AVI-249Multiples vulnérabilités dans Tenable Nessus

De multiples vulnérabilités ont été découvertes dans Tenable Nessus. Elles permettent à un attaquant de provoquer un déni de service à distance et une atteinte à la confidentialité des données.

Official advisory ↗
CERT-FR · French · CERTFR-2019-AVI-657Multiples vulnérabilités dans Tenable.sc

.org/CVERecord?id=CVE-2018-1283 Référence CVE CVE-2018-1301 https://www.cve.org/CVERecord?id=CVE-2018-1301 Référence CVE CVE-2018-1302 https://www.cve.org/CVERecord?id=CVE-2018-1302 Référence CVE CVE-2018-1303 https://www.cve.org/CVERecord?id=CVE-2018-1303 Référence CVE CVE-2018-1312 https://www.cve.org/CVERecord?id=CVE-2018-1312 Référence CVE CVE-2018-1333 https://www.cve.org/CVERecord?id=CVE-2018-1333 Référence CVE CVE-2018-17189 https://www.cve.org/CVERecord?id=CVE-2018-17189 Référence CVE CVE-2018-17199 https://www.cve.org/CVERecord?id=CVE-2018-17199 Référence CVE CVE-2019-1547 https://www.cve.org/CVERecord?id=CVE-2019-1547 Référence CVE CVE-2019-1551 https://www.cve.org/CVERecord?id=CVE-2019-1551 Référence CVE CVE-2019-1552 https://www.cve.org/CVERecord?id=CVE-2019-1552 Référence CVE CVE-2019-1563 https://www.cve.org/CVERecord?id=CVE-2019-1563 Référence CVE CVE-2019-3465 https://www.cve.org/CVERecord?id=CVE-2019-3465 Gestion détaillée du document le 31 décembre 2019 Version initiale Alertes Avis Bulletins d’actualités Mentions légales Conditions générales À propos Contact cyber.gouv.fr service-public.fr legifrance.gouv.fr info.gouv.fr france.fr info.gouv.fr/risques Premier Ministre / Secrétariat Général de la Défense et de la Sécurité Nationale / Agence nationale de la sécurité des systè

Official advisory ↗
CERT-FR · French · CERTFR-2019-AVI-611Vulnérabilité dans OpenSSL

Une vulnérabilité a été découverte dans OpenSSL. Elle permet à un attaquant de provoquer une atteinte à la confidentialité des données.

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2020-005743Cosminexus HTTP Server における脆弱性

Cosminexus HTTP Server には脆弱性 (CVE-2019-1551) が存在します。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2019-012631OpenSSL における整数オーバーフローの脆弱性

OpenSSL には、整数オーバーフローの脆弱性が存在します。 OpenSSL Project より、OpenSSL Security Advisory [6 December 2019] が公開されました。 深刻度 - 低 (Severity: Low) 512 ビット用モジュールのべき乗計算で使用される Montgomery squaring プロシージャにおけるオーバーフローの問題 - CVE-2019-1551

Official advisory ↗
03

Patch and workaround

Operational remediation based on structured source evidence.

Status
?Patch availability is based on structured fixed-version fields and authoritative update references. If no fix is verified, check the vendor advisory before making a change.
Patch available
Affected
OpenSSL: Fixed in OpenSSL 1.1.1e (Affected 1.1.1-1.1.1d), Fixed in OpenSSL 1.0.2u (Affected 1.0.2-1.0.2t)
Fixed
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
Action
Apply the fixed release for the affected product branch as recorded by Red Hat Product Security. Validate the exact product and build in the linked advisory before deployment.
Workaround
No verified workaround is recorded. If business-safe, reduce exposure to the affected interface and allow only trusted sources until authoritative guidance is available.
04

Evidence and provenance

Published 6 Dec 2019 · Last source change 16 Sept 2024, 19:40 UTC · CWE-190 · Integer Overflow or Wraparound

CVE recordCVE.org · 5.1
CVSS sourceNIST NVD
EPSS source
?The date BlackTree first stored a score for this CVE from the daily FIRST EPSS feed.
FIRST · tracked since 2026-09-01
European sourceENISA EUVD · EUVD-2019-10108
Product sourceCNA
Remediation sourceCVE/CNA references
CWE sourceNIST NVD
NVD statusNVD modified after enrichment

Core structured fields are present and their contributing authorities are shown above.

Material change intelligence

What changed after publication

View recent updates ↗
  1. Vendor guidanceAuthoritative vendor guidance changed from remediation: access.redhat.com/CVE-2019-1551 to advisory no longer present in the provider's current catalogue.
    Before
    remediation: access.redhat.com/CVE-2019-1551
    After
    advisory no longer present in the provider's current catalogue
    Red Hat Product Security ↗
  2. Affected versionsThe structured affected or fixed version information changed.
    Before
    Fixed in OpenSSL 1.1.1e (Affected 1.1.1-1.1.1d); Fixed in OpenSSL 1.0.2u (Affected 1.0.2-1.0.2t) · Fixed: An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
    After
    Fixed in OpenSSL 1.1.1e (Affected 1.1.1-1.1.1d); Fixed in OpenSSL 1.0.2u (Affected 1.0.2-1.0.2t) · Fixed: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
    Red Hat Product Security ↗
  3. ENISA EUVD mappingEUVD-2019-10108 was added to the official ENISA EUVD mapping for this CVE.
    Before
    not recorded
    After
    {"euvdId":"EUVD-2019-10108"}
    ENISA EUVD ↗
  4. Vendor guidanceAuthoritative vendor guidance changed: added patch: oracle.com/cpuApr2021.html; added patch: oracle.com/cpujan2021.html; removed vendor advisory: debian.org/dsa-4594; removed vendor advisory: debian.org/dsa-4855; 3 further additions; 7 further removals.
    Before
    vendor advisory: debian.org/dsa-4594 · vendor advisory: debian.org/dsa-4855 · vendor advisory: lists.fedoraproject.org/DDHOAATPWJCXRNFMJ2SASDBBNU5RJONY · 6 more references
    After
    patch: oracle.com/cpuApr2021.html · patch: oracle.com/cpujan2021.html · patch: oracle.com/cpujul2020.html · 2 more references
    oracle.com ↗
  5. Affected versionsThe structured affected or fixed version information changed.
    Before
    Fixed in OpenSSL 1.1.1e (Affected 1.1.1-1.1.1d); Fixed in OpenSSL 1.0.2u (Affected 1.0.2-1.0.2t) · Fixed: No fixed version is explicitly recorded in the structured CVE data.
    After
    Fixed in OpenSSL 1.1.1e (Affected 1.1.1-1.1.1d); Fixed in OpenSSL 1.0.2u (Affected 1.0.2-1.0.2t) · Fixed: An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
    CNA ↗
  6. Remediation statusRemediation status changed from Awaiting fix to Patch available.
    Before
    Awaiting fix
    After
    Patch available
    oracle.com ↗
  7. SeveritySeverity changed from Unknown to Medium.
    Before
    Unknown
    After
    Medium
    NIST NVD ↗
  8. CVSS scoreCVSS score changed from not recorded to 5.3 (CVSS 3.1 · NIST NVD · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
    Before
    not recorded
    After
    5.3 (CVSS 3.1 · NIST NVD · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
    NIST NVD ↗
  9. Catalogue recordCVE added to the BlackTree catalogue.
    CNA ↗
Material fields only · duplicate refreshes suppressed · history retained for the configured operational retention period
Technical terms and abbreviations used in this report
CVE
Common Vulnerabilities and Exposures: the public identifier for one disclosed vulnerability.
CVSS
Common Vulnerability Scoring System: a technical severity framework; it is not patching priority by itself.
EPSS
Exploit Prediction Scoring System: FIRST's estimate of the probability that exploitation activity will be observed in the next 30 days; it is a forecast, not confirmation.
CWE
Common Weakness Enumeration: the standard category describing the underlying software or hardware weakness.
CNA
CVE Numbering Authority: an organisation authorised to assign and publish CVE records.
CISA ADP
Cybersecurity and Infrastructure Security Agency Authorized Data Publisher: structured enrichment added to a CVE record.
NVD
National Vulnerability Database: NIST's enrichment service for CVE records.
CERT / CSIRT
A computer security incident response team that publishes warnings or coordinates incident response.
PoC
Proof of concept: public material that demonstrates or helps reproduce exploitation.
CSAF
Common Security Advisory Framework: a machine-readable format for security advisories.
LoTL
Living off the land: abuse of legitimate tools or system functions during an attack.
Free version - for non-commercial use only.CVE-2019-1551 · cve.blacktree.nl