CVE-2020-1968
The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections which have used a Diffie-Hellman (DH) based ciphersuite. In such a case this would result in the attacker being able to eavesdrop on all encrypted communications sent over that TLS connection. The attack can only be exploited if an implementation re-uses a DH secret across multiple TLS connections. Note that this issue only impacts DH ciphersuites and not ECDH ciphersuites. This issue affects OpenSSL 1.0.2 which is out of support and no longer receiving public updates. OpenSSL 1.1.1 is not vulnerable to this issue. Fixed in OpenSSL 1.0.2w (Affected 1.0.2-1.0.2v).
Published:Sep 9, 2020
Last Modified:Apr 16, 2026
EPS:Sep 9, 2020
EPSS Score:0.01042
CVSS Score:3.7
Affected Products
Vendor
Product
Action
Vendor
Canonical
Product
Ubuntu Linux
Canonical
Ubuntu Linux
Vendor
Debian
Product
Debian Linux
Debian
Debian Linux
Vendor
Fujitsu
Product
M10-1
Fujitsu
M10-1
Vendor
Fujitsu
Product
M10-1 Firmware
Fujitsu
M10-1 Firmware
Vendor
Fujitsu
Product
M10-4
Fujitsu
M10-4
Vendor
Fujitsu
Product
M10-4 Firmware
Fujitsu
M10-4 Firmware
Vendor
Fujitsu
Product
M10-4s
Fujitsu
M10-4s
Vendor
Fujitsu
Product
M10-4s Firmware
Fujitsu
M10-4s Firmware
Vendor
Fujitsu
Product
M12-1
Fujitsu
M12-1
Vendor
Fujitsu
Product
M12-1 Firmware
Fujitsu
M12-1 Firmware
Vendor
Fujitsu
Product
M12-2
Fujitsu
M12-2
Vendor
Fujitsu
Product
M12-2 Firmware
Fujitsu
M12-2 Firmware
Vendor
Fujitsu
Product
M12-2s
Fujitsu
M12-2s
Vendor
Fujitsu
Product
M12-2s Firmware
Fujitsu
M12-2s Firmware
Vendor
Openssl
Product
Openssl
Openssl
Openssl
Vendor
Oracle
Product
Ethernet Switch Es1-24
Oracle
Ethernet Switch Es1-24
Vendor
Oracle
Product
Ethernet Switch Es1-24 Firmware
Oracle
Ethernet Switch Es1-24 Firmware
Vendor
Oracle
Product
Ethernet Switch Es2-64
Oracle
Ethernet Switch Es2-64
Vendor
Oracle
Product
Ethernet Switch Es2-64 Firmware
Oracle
Ethernet Switch Es2-64 Firmware
Vendor
Oracle
Product
Ethernet Switch Es2-72
Oracle
Ethernet Switch Es2-72
Vendor
Oracle
Product
Ethernet Switch Es2-72 Firmware
Oracle
Ethernet Switch Es2-72 Firmware
Vendor
Oracle
Product
Ethernet Switch Tor-72
Oracle
Ethernet Switch Tor-72
Vendor
Oracle
Product
Ethernet Switch Tor-72 Firmware
Oracle
Ethernet Switch Tor-72 Firmware
Vendor
Oracle
Product
Jd Edwards World Security
Oracle
Jd Edwards World Security
Vendor
Oracle
Product
Peoplesoft Enterprise Peopletools
Oracle
Peoplesoft Enterprise Peopletools
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
