Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-1551

28
FAUCET Score

CVE-2019-1551 describes an overflow bug in the x64_64 Montgomery squaring procedure within OpenSSL versions 1.1.1 through 1.1.1d and 1.0.2 through 1.0.2t, affecting exponentiation with 512-bit moduli. While RSA and DSA attacks are unlikely, attacks against DH512 are considered feasible if the private key is reused, and applications using BN_mod_exp with BN_FLG_CONSTTIME may also be vulnerable. Rated Medium (CVSS 5.3), this vulnerability has a network attack vector with low complexity, potentially leading to information disclosure. The primary impact is on confidentiality, with no integrity or availability impact. There is no evidence of active exploitation, no public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage, suggesting low current threat activity.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.0.2, <= 1.0.2tCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
>= 1.1.1, <= 1.1.1dCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
15.1CPE matchmatch criteria
cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*
12.4.0.0CPE matchmatch criteria
cpe:2.3:a:oracle:enterprise_manager_ops_center:12.4.0.0:*:*:*:*:*:*:*
<= 4.0.12CPE matchmatch criteria
cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
14.30%
Probability of exploitation in next 30 days
EPSS Percentile
96.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.1430 is in the 96th percentile among its peer group of 23,690 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (32)

oraclepatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-apr-0:1.6.3-104.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-apr-util-0:1.6.1-75.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-brotli-0:1.0.6-38.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-curl-0:7.64.1-44.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-httpd-0:2.4.37-64.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-jansson-0:2.11-53.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-mod_cluster-native-0:1.3.14-11.Final_redhat_2.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-mod_http2-0:1.15.7-11.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-mod_jk-0:1.2.48-10.redhat_1.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-mod_md-1:2.0.8-30.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-mod_security-0:2.9.2-57.GA.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-nghttp2-0:1.39.2-34.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-openssl-1:1.1.1c-32.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-apr-0:1.6.3-104.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-apr-util-0:1.6.1-75.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-brotli-0:1.0.6-38.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-curl-0:7.64.1-44.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-httpd-0:2.4.37-64.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-jansson-0:2.11-53.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_cluster-native-0:1.3.14-11.Final_redhat_2.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_http2-0:1.15.7-11.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_jk-0:1.2.48-10.redhat_1.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_md-1:2.0.8-30.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_security-0:2.9.2-57.GA.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-nghttp2-0:1.39.2-34.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-openssl-1:1.1.1c-32.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-openssl-chil-0:1.0.0-1.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: openssl-1:1.1.1g-11.el8
View patch
redhatpatch availablevia redhat_api
Product: Text-Only JBCSFixed in: openssl
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: openssl
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: compat-openssl10

Vendor Advisories (2)

microsoft2019-Dec/CVE-2019-1551Moderate

rsaz_512_sqr overflow bug on x86_64

Dec 10, 2019
redhatCVE-2019-1551Low

openssl: Integer overflow in RSAZ modular exponentiation on x86_64

Dec 6, 2019

References

lists.opensuse.org / opensuse-security-announce/2020-01/msg00030.html
Mailing ListThird Party Advisory
packetstormsecurity.com / files/155754/Slackware-Security-Advisory-openssl-Updates.html
Third Party AdvisoryVDB Entry
git.openssl.org / gitweb
git.openssl.org / gitweb
lists.debian.org / debian-lts-announce/2022/03/msg00023.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/DDHOAATPWJCXRNFMJ2SASDBBNU5RJONY
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/EXDDAOWSAIEFQNBHWYE6PPYFV4QXGMCD
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/XVEP3LAK4JSPRXFO4QF4GG2IVXADV3SO
seclists.org / bugtraq/2019/Dec/39
Mailing ListThird Party Advisory
seclists.org / bugtraq/2019/Dec/46
Mailing ListThird Party Advisory
security.gentoo.org / glsa/202004-10
Third Party Advisory
security.netapp.com / advisory/ntap-20191210-0001
Third Party Advisory
usn.ubuntu.com / 4376-1
Third Party Advisory
usn.ubuntu.com / 4504-1
Third Party Advisory
debian.org / security/2019/dsa-4594
Third Party Advisory
debian.org / security/2021/dsa-4855
Third Party Advisory
openssl.org / news/secadv/20191206.txt
Vendor Advisory
oracle.com / security-alerts/cpuApr2021.html
PatchThird Party Advisory
oracle.com / security-alerts/cpujan2021.html
PatchThird Party Advisory
oracle.com / security-alerts/cpujul2020.html
PatchThird Party Advisory
tenable.com / security/tns-2019-09
Third Party Advisory
tenable.com / security/tns-2020-03
Third Party Advisory
tenable.com / security/tns-2020-11
Third Party Advisory
tenable.com / security/tns-2021-10
Third Party Advisory