Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:20936
HistoryJul 31, 2019 - 7:19 a.m.

Insecure Path Defaults

2019-07-3107:19:43
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
175

0.001 Low

EPSS

Percentile

19.7%

OpenSSL has Insecure Path Defaults. When installed on a Windows machine, the default OPENSSLDIR is C:/usr/local which is world writable. This allows an attacker to modify OpenSSL’s default configuration, insert CA certificates, modify (or even replace) existing engine modules, etc.

CPENameOperatorVersion
opensslle1.0.210
opensslle1.0.210

References