CVE-2020-1968
3.7
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.2 / Impact: 1.4
Source: NVD
Description
The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections which have used a Diffie-Hellman (DH) based ciphersuite. In such a case this would result in the attacker being able to eavesdrop on all encrypted communications sent over that TLS connection. The attack can only be exploited if an implementation re-uses a DH secret across multiple TLS connections. Note that this issue only impacts DH ciphersuites and not ECDH ciphersuites. This issue affects OpenSSL 1.0.2 which is out of support and no longer receiving public updates. OpenSSL 1.1.1 is not vulnerable to this issue. Fixed in OpenSSL 1.0.2w (Affected 1.0.2-1.0.2v).
Affected (24)
Show all products
Openssl: Openssl · Canonical: Ubuntu Linux · Debian: Debian Linux · Oracle: Jd Edwards World Security, Peoplesoft Enterprise Peopletools, Ethernet Switch Es2 64 Firmware, Ethernet Switch Es2 72 Firmware, Ethernet Switch Es1 24 Firmware, Ethernet Switch Tor 72 Firmware · Fujitsu: M10 1 Firmware, M10 4 Firmware, M10 4s Firmware, M12 1 Firmware, M12 2 Firmware, M12 2s Firmware
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 16.04 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 9.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version a9.4 | |
| Version 8.56 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.0.0.14 |
| Running on/with | Platform Versions |
|---|---|
Oracle Ethernet Switch Es2 64 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.0.0.14 |
| Running on/with | Platform Versions |
|---|---|
Oracle Ethernet Switch Es2 72 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp2400 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp2400 |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp2400 |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp2400 |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp2400 |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp2400 |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp3100 |
| Running on/with | Platform Versions |
|---|---|
Fujitsu M10 1 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp3100 |
| Running on/with | Platform Versions |
|---|---|
Fujitsu M10 4 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp3100 |
| Running on/with | Platform Versions |
|---|---|
Fujitsu M10 4s | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp3100 |
| Running on/with | Platform Versions |
|---|---|
Fujitsu M12 1 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp3100 |
| Running on/with | Platform Versions |
|---|---|
Fujitsu M12 2 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp3100 |
| Running on/with | Platform Versions |
|---|---|
Fujitsu M12 2s | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.3.1 |
| Running on/with | Platform Versions |
|---|---|
Oracle Ethernet Switch Es1 24 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.2.2 |
| Running on/with | Platform Versions |
|---|---|
Oracle Ethernet Switch Tor 72 | All versions |
References (20)
Source: openssl-security@openssl.org
Mailing ListThird Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
PatchThird Party Advisory
Source: openssl-security@openssl.org
PatchThird Party Advisory
Source: openssl-security@openssl.org
PatchThird Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Timeline
No history available yet.