The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections which have used a Diffie-Hellman (DH) based ciphersuite. In such a case this would result in the attacker being able to eavesdrop on all encrypted communications sent over that TLS connection. The attack can only be exploited if an implementation re-uses a DH secret across multiple TLS connections. Note that this issue only impacts DH ciphersuites and not ECDH ciphersuites. This issue affects OpenSSL 1.0.2 which is out of support and no longer receiving public updates. OpenSSL 1.1.1 is not vulnerable to this issue. Fixed in OpenSSL 1.0.2w (Affected 1.0.2-1.0.2v).
CVSS Details
- CVSS 3.1 Base Score: 3.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade openssl | Sep 28, 2020 | Sep 9, 2020 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Dec 11, 2020 |
| Gentoo Linux | — | Upgrade dev-libs/openssl. | Oct 17, 2022 | Sep 9, 2020 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Sep 11, 2020 | Sep 9, 2020 |
| Ibm Aix | — | Apply the fix or workaround for openssl_advisory32 | Feb 2, 2021 | Sep 9, 2020 |
| Oracle Solaris | — | Upgrade library/security/openssl/openssl-fips-140 to version 2.0.15-0.175.3.36.0.27.0 on Solaris 11.3Upgrade library/security/openssl to version 1.0.2.24-11.4.30.0.1.88.0 on Solaris 11.4Upgrade library/security/openssl/openssl-fips-140 to version 2.0.15-11.4.30.0.1.88.0 on Solaris 11.4Upgrade library/security/openssl to version 1.0.2.26-0.175.3.36.0.27.0 on Solaris 11.3Upgrade library/security/openssl-11 to version 1.1.1.9-11.4.30.0.1.88.0 on Solaris 11.4 | Feb 17, 2021 | Sep 9, 2020 |
| Panos | — | Update PAN-OS 9.0 to the latest workaround for your deviceUpdate PAN-OS 8.1 to the latest workaround for your deviceUpdate PAN-OS 9.1 to the latest workaround for your device | Oct 14, 2021 | Sep 9, 2020 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 9, 2020 |
| Suse | — | Upgrade openssl1-docUpgrade opensslUpgrade libopenssl0_9_8-hmacUpgrade libopenssl1_0_0Upgrade openssl1Upgrade libopenssl1_0_0-32bitUpgrade openssl-docUpgrade libopenssl0_9_8-32bitUpgrade libopenssl1-develUpgrade libopenssl1_0_0-x86Upgrade libopenssl0_9_8-hmac-32bitUpgrade libopenssl0_9_8 | Sep 16, 2020 | Sep 9, 2020 |
| Ubuntu | — | Upgrade libssl1.0.0 (Ubuntu Pro)Upgrade libssl1.0.0Upgrade openssl (Ubuntu Pro) | Sep 17, 2020 | Sep 9, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Sep 9, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub