← Back

CVE-2020-1968

nvd nist
Published: Sep 9, 2020Modified: Jun 17, 2026

JSON object

Loading...
3.7
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.2 / Impact: 1.4
Source: NVD

Description

The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections which have used a Diffie-Hellman (DH) based ciphersuite. In such a case this would result in the attacker being able to eavesdrop on all encrypted communications sent over that TLS connection. The attack can only be exploited if an implementation re-uses a DH secret across multiple TLS connections. Note that this issue only impacts DH ciphersuites and not ECDH ciphersuites. This issue affects OpenSSL 1.0.2 which is out of support and no longer receiving public updates. OpenSSL 1.1.1 is not vulnerable to this issue. Fixed in OpenSSL 1.0.2w (Affected 1.0.2-1.0.2v).

Affected (24)

Show all products
1 product
Openssl
1 product
Ubuntu Linux
1 product
Debian Linux
6 products
Jd Edwards World Security
Peoplesoft Enterprise Peopletools
Ethernet Switch Es2 64 Firmware
Ethernet Switch Es2 72 Firmware
Ethernet Switch Es1 24 Firmware
Ethernet Switch Tor 72 Firmware
6 products
M10 1 Firmware
M10 4 Firmware
M10 4s Firmware
M12 1 Firmware
M12 2 Firmware
M12 2s Firmware
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 1.0.2 to 1.0.2v
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 16.04
Version 18.04
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 9.0
Configuration D
4 vulnerable
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 2.0.0.14
Running on/withPlatform Versions
Oracle
Ethernet Switch Es2 64
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 2.0.0.14
Running on/withPlatform Versions
Oracle
Ethernet Switch Es2 72
All versions
Configuration G
1 vulnerable
Vulnerable SoftwareAffected Versions
Before xcp2400
Configuration H
1 vulnerable
Vulnerable SoftwareAffected Versions
Before xcp2400
Configuration I
1 vulnerable
Vulnerable SoftwareAffected Versions
Before xcp2400
Configuration J
1 vulnerable
Vulnerable SoftwareAffected Versions
Before xcp2400
Configuration K
1 vulnerable
Vulnerable SoftwareAffected Versions
Before xcp2400
Configuration L
1 vulnerable
Vulnerable SoftwareAffected Versions
Before xcp2400
Configuration M
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before xcp3100
Running on/withPlatform Versions
Fujitsu
M10 1
All versions
Configuration N
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before xcp3100
Running on/withPlatform Versions
Fujitsu
M10 4
All versions
Configuration O
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before xcp3100
Running on/withPlatform Versions
Fujitsu
M10 4s
All versions
Configuration P
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before xcp3100
Running on/withPlatform Versions
Fujitsu
M12 1
All versions
Configuration Q
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before xcp3100
Running on/withPlatform Versions
Fujitsu
M12 2
All versions
Configuration R
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before xcp3100
Running on/withPlatform Versions
Fujitsu
M12 2s
All versions
Configuration S
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.3.1
Running on/withPlatform Versions
Oracle
Ethernet Switch Es1 24
All versions
Configuration T
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.2.2
Running on/withPlatform Versions
Oracle
Ethernet Switch Tor 72
All versions

References (20)

Source: openssl-security@openssl.org
Mailing ListThird Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Vendor Advisory
Source: openssl-security@openssl.org
PatchThird Party Advisory
Source: openssl-security@openssl.org
PatchThird Party Advisory
Source: openssl-security@openssl.org
PatchThird Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.