cbcvebase.
CVE-2020-1968
published 2020-09-09

CVE-2020-1968: The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections which have…

low3.7CVSS 3.1
AVNACHPRNUINSUCLINAN
The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections which have used a Diffie-Hellman (DH) based ciphersuite. In such a case this would result in the attacker being able to eavesdrop on all encrypted communications sent over that TLS connection. The attack can only be exploited if an implementation re-uses a DH secret across multiple TLS connections. Note that this issue only impacts DH ciphersuites and not ECDH ciphersuites. This issue affects OpenSSL 1.0.2 which is out of support and no longer receiving public updates. OpenSSL 1.1.1 is not vulnerable to this issue. Fixed in OpenSSL 1.0.2w (Affected 1.0.2-1.0.2v).

Affected

35 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianopenssl< openssl 1.1.0c-1 (bookworm)openssl 1.1.0c-1 (bookworm)
fujitsum10-1_firmware< xcp2400xcp2400
fujitsum10-1_firmware< xcp3100xcp3100
fujitsum10-4_firmware< xcp2400xcp2400
fujitsum10-4_firmware< xcp3100xcp3100
fujitsum10-4s_firmware< xcp2400xcp2400
fujitsum10-4s_firmware< xcp3100xcp3100
fujitsum12-1_firmware< xcp2400xcp2400
fujitsum12-1_firmware< xcp3100xcp3100
fujitsum12-2_firmware< xcp2400xcp2400
fujitsum12-2_firmware< xcp3100xcp3100
fujitsum12-2s_firmware< xcp2400xcp2400
fujitsum12-2s_firmware< xcp3100xcp3100
opensslopenssl
opensslopenssl>= 0 < 1.1.0c-11.1.0c-1
opensslopenssl>= 0 < 1.1.0c-11.1.0c-1
opensslopenssl>= 0 < 1.1.0c-11.1.0c-1
opensslopenssl>= 0 < 1.1.0c-11.1.0c-1
opensslopenssl>= 0 < 1.0.2g-1ubuntu4.171.0.2g-1ubuntu4.17
opensslopenssl>= 0 < 1.0.1f-1ubuntu2.27+esm101.0.1f-1ubuntu2.27+esm10
opensslopenssl1.0.2 – 1.0.2v
oracleethernet_switch_es1-24_firmware

CVSS provenance

nvdv3.13.7LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
osv4.7MEDIUM