Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-1552

18
FAUCET Score

CVE-2019-1552 describes a low-severity vulnerability in OpenSSL versions 1.0.2, 1.1.0, and 1.1.1, specifically impacting Windows builds (mingw and Visual C). The issue stems from OpenSSL's default configuration directory (OPENSSLDIR) being set to a Unix-like path (e.g., '/usr/local') even on Windows, leading to programs looking in 'C:/usr/local'. This directory can be world-writable, allowing untrusted users to modify OpenSSL's configuration, insert malicious CA certificates, or replace engine modules. The CVSS score is 3.3 (LOW), indicating a local attack vector with low complexity, requiring low privileges, and resulting in low integrity impact (e.g., unauthorized modification of configuration). There is no confidentiality or availability impact. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness and attention.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.0.2, <= 1.0.2sCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
>= 1.1.0, <= 1.1.0kCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
>= 1.1.1, <= 1.1.1cCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

3.3LOW

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
1.8
Impact Score
1.4
CvssVersion
3.0

Exploit Intelligence

EPSS Score
0.68%
Probability of exploitation in next 30 days
EPSS Percentile
48.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0068 is in the 97th percentile among its peer group of 1,511 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2019-1552Low

openssl: Insecure path defaults vulnerability in mingw builds

Jul 30, 2019

References

cert-portal.siemens.com / productcert/pdf/ssa-412672.pdf
git.openssl.org / gitweb
git.openssl.org / gitweb
git.openssl.org / gitweb
git.openssl.org / gitweb
kc.mcafee.com / corporate/index
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/EWC42UXL5GHTU5G77VKBF6JYUUNGSHOM
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/Y3IVFGSERAZLNJCK35TEM2R4726XIH3Z
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/ZBEV5QGDRFUZDMNECFXUSN5FMYOZDE4V
security.netapp.com / advisory/ntap-20190823-0006
support.f5.com / csp/article/K94041354
support.f5.com / csp/article/K94041354
kb.cert.org / vuls/id/429301
openssl.org / news/secadv/20190730.txt
Vendor Advisory
oracle.com / security-alerts/cpuapr2020.html
oracle.com / security-alerts/cpujan2020.html
oracle.com / security-alerts/cpujul2020.html
oracle.com / security-alerts/cpuoct2020.html
oracle.com / technetwork/security-advisory/cpuoct2019-5072832.html
tenable.com / security/tns-2019-08
tenable.com / security/tns-2019-09