CVE-2019-1549 describes a vulnerability in OpenSSL versions 1.1.1 through 1.1.1c, where the newly rewritten random number generator (RNG) failed to properly protect against shared state between parent and child processes after a fork() system call. This could lead to predictable RNG outputs in certain scenarios. Rated as MEDIUM severity (CVSS 5.3), the vulnerability has a network attack vector and low attack complexity, potentially leading to a loss of confidentiality (C:L). However, a high-precision timer partially mitigates the issue by mixing additional entropy into the RNG state. There is no evidence of active exploitation, and no public exploit code is available (Metasploit, Nuclei, ExploitDB). Community discussion and media coverage for this CVE are minimal, indicating low public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.1.1, <= 1.1.1cCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.