CVE-2020-1968, known as the Raccoon attack, is a low-severity vulnerability in the TLS specification affecting OpenSSL 1.0.2 and other products like Canonical and Debian. It allows an attacker to compute the pre-master secret in Diffie-Hellman (DH) based ciphersuites, enabling eavesdropping on encrypted communications if a DH secret is reused across multiple TLS connections. The attack has a network attack vector and high complexity, with a low impact on confidentiality and no impact on integrity or availability. There is no evidence of active exploitation, public exploit code, or significant community attention beyond a single Reddit mention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0.2, <= 1.0.2vCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* | ||
18.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
a9.4CPE matchmatch criteria | cpe:2.3:a:oracle:jd_edwards_world_security:a9.4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.