Rapid7
BACK TO VEDB

CVE-2020-1968: Observable Discrepancy

REQUEST DEMO

The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections which have used a Diffie-Hellman (DH) based ciphersuite. In such a case this would result in the attacker being able to eavesdrop on all encrypted communications sent over that TLS connection. The attack can only be exploited if an implementation re-uses a DH secret across multiple TLS connections. Note that this issue only impacts DH ciphersuites and not ECDH ciphersuites. This issue affects OpenSSL 1.0.2 which is out of support and no longer receiving public updates. OpenSSL 1.1.1 is not vulnerable to this issue. Fixed in OpenSSL 1.0.2w (Affected 1.0.2-1.0.2v).

CVSS Details

  • CVSS 3.1 Base Score: 3.7
  • CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)

Covered by Rapid7

ProductVendor AdvisorySolution FileAddedPublished
Debian
View advisory ↗
debian-upgrade-openssl
Sep 28, 2020Sep 9, 2020
F5 Big Ip
View advisory ↗View advisory ↗
f5-bigip-upgrade-latest
Jun 17, 2026Dec 11, 2020
Gentoo Linux
View advisory ↗
gentoo-linux-upgrade-dev-libs-openssl
Oct 17, 2022Sep 9, 2020
Http Openssl
View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗
openssl-upgrade-latest
Sep 11, 2020Sep 9, 2020
Ibm Aix
View advisory ↗View advisory ↗
ibm-aix-openssl_advisory32
Feb 2, 2021Sep 9, 2020
Oracle Solaris
View advisory ↗
oracle-solaris-11-3-upgrade-library-security-openssl-1-0-2-26-0-175-3-36-0-27-0oracle-solaris-11-3-upgrade-library-security-openssl-openssl-fips-140-2-0-15-0-175-3-36-0-27-0oracle-solaris-11-4-upgrade-library-security-openssl-1-0-2-24-11-4-30-0-1-88-0oracle-solaris-11-4-upgrade-library-security-openssl-11-1-1-1-9-11-4-30-0-1-88-0oracle-solaris-11-4-upgrade-library-security-openssl-openssl-fips-140-2-0-15-11-4-30-0-1-88-0
Feb 17, 2021Sep 9, 2020
Panos
View advisory ↗
palo-alto-networks-pan-os-upgrade-8-1palo-alto-networks-pan-os-upgrade-9-0palo-alto-networks-pan-os-upgrade-9-1
Oct 14, 2021Sep 9, 2020
Redhat_linux
View advisory ↗
no-fix-redhat-rpm-package
Jul 9, 2025Sep 9, 2020
Suse—
suse-upgrade-libopenssl0_9_8suse-upgrade-libopenssl0_9_8-32bitsuse-upgrade-libopenssl0_9_8-hmacsuse-upgrade-libopenssl0_9_8-hmac-32bitsuse-upgrade-libopenssl1-develsuse-upgrade-libopenssl1_0_0suse-upgrade-libopenssl1_0_0-32bitsuse-upgrade-libopenssl1_0_0-x86suse-upgrade-opensslsuse-upgrade-openssl-docsuse-upgrade-openssl1suse-upgrade-openssl1-doc
Sep 16, 2020Sep 9, 2020
Ubuntu
View advisory ↗
ubuntu-pro-upgrade-libssl1-0-0ubuntu-pro-upgrade-opensslubuntu-upgrade-libssl1-0-0
Sep 17, 2020Sep 9, 2020
Vmware Photon_os
View advisory ↗
vmware-photon_os_update_tdnf
Jan 20, 2025Sep 9, 2020

Prioritise with Active Threat Intelligence

With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.

Explore Intelligence Hub

CVE details

CVSS v4 ScoreN/A
CVSS v3 Score3.7 Low
EPSS Score5%
EPSS Percentile91%
In CISA KEV CatalogueFalse

Published

Sep 9, 2020

References

  • NVD ↗
    Rapid7
    Request Demo
    • Request Demo
    • Explore platform
    • Exposure Management
    • Attack Surface Management
    • Vulnerability Management
    • Cloud-Native Application Protection
    • Application Security
    • Next-Gen SIEM
    • Threat Intelligence Platform
    • Start a Free Trial
    • AI-Engine
    • Rapid7 Labs
    • Self-Guided Platform Tour
    • Talk to an Expert
    • Rapid7 Threat Intelligence
    • All Products
    • Managed Detection and Response
    • MDR for Microsoft
    • MDR for Enterprise
    • Incident Response Services
    • Rapid7 vs. Them
    • Customer Stories
    • MDR Product Tour
    • MDR ROI Calculator
    • Managed Vulnerability Management
    • Continuous Red Teaming
    • Managed Application Security
    • Penetration Testing Services
    • All services
    • READ NOW
    • Rapid7 Labs
    • Emergent Threat Response
    • Vulnerability & Exploit Database
    • Blog
    • Webinars and Events
    • Resource Library
    • Cybersecurity Fundamentals
    • Product Documentation
    • Product Release Notes
    • Product Extensions
    • Product Toolkits
    • Customer Support
    • Rapid7 Forum
    • Partnerships Overview
    • PACT Partner Program
    • PACT for Service Providers
    • Partner Directory
    • Technology Partners
    • AWS Partnership
    • Partner Login
    • Become a Partner
    • Become a partner
    • About Us
    • Leadership Team
    • Our Customers
    • Careers
    • Contact Us
    • Newsroom
    • Awards and Recognition
    • Investors
    • Social Good
    • Culture
    • Boston Bruins Partnership
    • Book live demo
    Rapid7

    Get Started

    Command Platform
    Exposure Management
    MDR Services
    Solutions

    Take Action

    Start a Free Trial
    Take a Product Tour
    Get Breach Support
    Contact Sales

    Company

    • About Us
    • Leadership
    • Newsroom
    • Our Customers
    • Partner Programs
    • Investors
    • Careers

    Stay Informed

    • Blog
    • Emergent Threat Response
    • Webinars & Events
    • Rapid7 Labs Research
    • Vulnerability Database
    • Security Fundamentals

    For Customers

    • Sign In
    • Support Portal
    • Product Documentation
    • Extension Library
    • Rapid7 Academy
    • Customer Escalation Portal

    Contact Support

    • +1-866-390-8113

    Follow Us

    LinkedIn icon
    LinkedIn
    X (Twitter) icon
    X (Twitter)
    Facebook icon
    Facebook
    Instagram icon
    Instagram
    Bluesky icon
    Bluesky
    © Rapid7
    Legal TermsPrivacy PolicyExport NoticeTrustCookie ListAccessibility Statement