There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH512 are considered just feasible. However, for an attack the target would have to re-use the DH512 private key, which is not recommended anyway. Also applications directly using the low level API BN_mod_exp may be affected if they use BN_FLG_CONSTTIME. Fixed in OpenSSL 1.1.1e (Affected 1.1.1-1.1.1d). Fixed in OpenSSL 1.0.2u (Affected 1.0.2-1.0.2t).
Conclusion & alert: CVE-2019-1551 is rated Moderate Risk (59.8/100): CVSS Medium severity, with high exploitation likelihood (EPSS 14.30%, 96th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. EPSS rose +11.50% over the last day, indicating growing attacker interest. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 2.80% | 14.30% | +11.50% |
| 2 | 2026-05-24 | 2.42% | 2.80% | +0.39% |
| 3 | 2026-04-22 | — | 2.42% | — |
Full EPSS history (65 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.3 | 3.1 | MEDIUM |
|
3.9 | 1.4 | [email protected] |
| 5.0 | 2.0 | MEDIUM |
|
10.0 | 2.9 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
medium | CVE-2019-1551: 3 source package rows (openssl, openssl1.1-compat, openssl3); 30 state rows across 13 repos (3.10-main, 3.11-main, 3.12-main, 3.17-community, 3.17-main, 3.18-community, 3.18-main, 3.19-main, 3.20-main, 3.21-main, 3.22-main, edge-community, edge-main); fixed 15, open 15. | https://security.alpinelinux.org/vuln/CVE-2019-1551 |
debian
|
low | CVE-2019-1551 low priority: Debian including 1 source packages (openssl), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2019-1551 |
gentoo
|
normal | CVE-2019-1551: 1 GLSA(s) (202004-10), 1 atom(s) (dev-libs/openssl); latest impact normal. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2019-1551 |
redhat
|
low | — | https://access.redhat.com/security/cve/CVE-2019-1551 |
suse
|
medium | CVE-2019-1551 severity moderate: SUSE including 460 source package names (0.1.0:libopenssl1_1-1.1.0i-14.6.1, 0.1.75:libopenssl1_1-1.1.0i-14.6.1, …), 999 product×package rows across 203 product lines (Container caasp/v4/389-ds, Container caasp/v4/busybox, … (203 product lines)): Fixed 571, Known Not Affected 271, Known Affected 157. | https://www.suse.com/security/cve/CVE-2019-1551/ |
ubuntu
|
low | CVE-2019-1551 low priority: Ubuntu including 4 source packages (edk2, nodejs, openssl, openssl1.0), 28 status rows across 7 suites (bionic, disco, eoan, focal, trusty, upstream, xenial): not-affected 11, DNE 6, released 6, needs-triage 3, ignored 2. | https://ubuntu.com/security/CVE-2019-1551 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| openssl | openssl | >= 1.0.2, <= 1.0.2t | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* |
| openssl | openssl | >= 1.1.1, <= 1.1.1d | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* |
| opensuse | leap | 15.1 | cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:* |
| oracle | enterprise_manager_ops_center | 12.4.0.0 | cpe:2.3:a:oracle:enterprise_manager_ops_center:12.4.0.0:*:*:*:*:*:*:* |
| oracle | mysql_enterprise_monitor | <= 4.0.12 | cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:* |
| oracle | mysql_enterprise_monitor | >= 8.0.0, <= 8.0.20 | cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:* |
| oracle | peoplesoft_enterprise_peopletools | 8.56 | cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.56:*:*:*:*:*:*:* |
| oracle | peoplesoft_enterprise_peopletools | 8.57 | cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*:*:*:*:*:* |
| oracle | peoplesoft_enterprise_peopletools | 8.58 | cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:* |
| canonical | ubuntu_linux | 16.04 | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* |
| canonical | ubuntu_linux | 18.04 | cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* |
| canonical | ubuntu_linux | 19.10 | cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:* |
| fedoraproject | fedora | 30 | cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:* |
| fedoraproject | fedora | 31 | cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* |
| fedoraproject | fedora | 32 | cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:* |
| debian | debian_linux | 9.0 | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
| debian | debian_linux | 10.0 | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
| tenable | log_correlation_engine | < 6.0.9 | cpe:2.3:a:tenable:log_correlation_engine:*:*:*:*:*:*:*:* |