LOW · 3.7

CVE-2020-1968

The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections which have used a Diffie-Hellman (DH) based ciphers...

Vulnerability Description

The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections which have used a Diffie-Hellman (DH) based ciphersuite. In such a case this would result in the attacker being able to eavesdrop on all encrypted communications sent over that TLS connection. The attack can only be exploited if an implementation re-uses a DH secret across multiple TLS connections. Note that this issue only impacts DH ciphersuites and not ECDH ciphersuites. This issue affects OpenSSL 1.0.2 which is out of support and no longer receiving public updates. OpenSSL 1.1.1 is not vulnerable to this issue. Fixed in OpenSSL 1.0.2w (Affected 1.0.2-1.0.2v).

CVSS Score

3.7

LOW

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
OpensslOpenssl>= 1.0.2, <= 1.0.2v
CanonicalUbuntu Linux16.04
DebianDebian Linux9.0
OracleJd Edwards World Securitya9.4
OraclePeoplesoft Enterprise Peopletools8.56
OracleEthernet Switch Es2-64 Firmware2.0.0.14
OracleEthernet Switch Es2-64-
OracleEthernet Switch Es2-72 Firmware2.0.0.14
OracleEthernet Switch Es2-72-
FujitsuM10-1 Firmware< xcp2400
FujitsuM10-1-
FujitsuM10-4 Firmware< xcp2400
FujitsuM10-4-
FujitsuM10-4S Firmware< xcp2400
FujitsuM10-4S-
FujitsuM12-1 Firmware< xcp2400
FujitsuM12-1-
FujitsuM12-2 Firmware< xcp2400
FujitsuM12-2-
FujitsuM12-2S Firmware< xcp2400

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-1968?

CVE-2020-1968 is a vulnerability with a CVSS score of 3.7 (LOW). The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections which have used a Diffie-Hellman (DH) based ciphers...

How severe is CVE-2020-1968?

CVE-2020-1968 has been rated LOW with a CVSS base score of 3.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-1968?

Check the references section above for vendor advisories and patch information. Affected products include: Openssl Openssl, Canonical Ubuntu Linux, Debian Debian Linux, Oracle Jd Edwards World Security, Oracle Peoplesoft Enterprise Peopletools.