The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections which have used a Diffie-Hellman (DH) based ciphersuite. In such a case this would result in the attacker being able to eavesdrop on all encrypted communications sent over that TLS connection. The attack can only be exploited if an implementation re-uses a DH secret across multiple TLS connections. Note that this issue only impacts DH ciphersuites and not ECDH ciphersuites. This issue affects OpenSSL 1.0.2 which is out of support and no longer receiving public updates. OpenSSL 1.1.1 is not vulnerable to this issue. Fixed in OpenSSL 1.0.2w (Affected 1.0.2-1.0.2v).
CVSS Details
- CVSS 3.1 Base Score: 3.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | debian-upgrade-openssl | Sep 28, 2020 | Sep 9, 2020 | |
| F5 Big Ip | f5-bigip-upgrade-latest | Jun 17, 2026 | Dec 11, 2020 | |
| Gentoo Linux | gentoo-linux-upgrade-dev-libs-openssl | Oct 17, 2022 | Sep 9, 2020 | |
| Http Openssl | openssl-upgrade-latest | Sep 11, 2020 | Sep 9, 2020 | |
| Ibm Aix | ibm-aix-openssl_advisory32 | Feb 2, 2021 | Sep 9, 2020 | |
| Oracle Solaris | oracle-solaris-11-3-upgrade-library-security-openssl-1-0-2-26-0-175-3-36-0-27-0oracle-solaris-11-3-upgrade-library-security-openssl-openssl-fips-140-2-0-15-0-175-3-36-0-27-0oracle-solaris-11-4-upgrade-library-security-openssl-1-0-2-24-11-4-30-0-1-88-0oracle-solaris-11-4-upgrade-library-security-openssl-11-1-1-1-9-11-4-30-0-1-88-0oracle-solaris-11-4-upgrade-library-security-openssl-openssl-fips-140-2-0-15-11-4-30-0-1-88-0 | Feb 17, 2021 | Sep 9, 2020 | |
| Panos | palo-alto-networks-pan-os-upgrade-8-1palo-alto-networks-pan-os-upgrade-9-0palo-alto-networks-pan-os-upgrade-9-1 | Oct 14, 2021 | Sep 9, 2020 | |
| Redhat_linux | no-fix-redhat-rpm-package | Jul 9, 2025 | Sep 9, 2020 | |
| Suse | — | suse-upgrade-libopenssl0_9_8suse-upgrade-libopenssl0_9_8-32bitsuse-upgrade-libopenssl0_9_8-hmacsuse-upgrade-libopenssl0_9_8-hmac-32bitsuse-upgrade-libopenssl1-develsuse-upgrade-libopenssl1_0_0suse-upgrade-libopenssl1_0_0-32bitsuse-upgrade-libopenssl1_0_0-x86suse-upgrade-opensslsuse-upgrade-openssl-docsuse-upgrade-openssl1suse-upgrade-openssl1-doc | Sep 16, 2020 | Sep 9, 2020 |
| Ubuntu | ubuntu-pro-upgrade-libssl1-0-0ubuntu-pro-upgrade-opensslubuntu-upgrade-libssl1-0-0 | Sep 17, 2020 | Sep 9, 2020 | |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Jan 20, 2025 | Sep 9, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub