Raccoon attack
Published Sep 9, 2020
5.9
MEDIUMCVSS 3.1
EPSS 4.90%
Description
The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections which have used a Diffie-Hellman (DH) based ciphersuite. In such a case this would result in the attacker being able to eavesdrop on all encrypted communications sent over that TLS connection. The attack can only be exploited if an implementation re-uses a DH secret across multiple TLS connections. Note that this issue only impacts DH ciphersuites and not ECDH ciphersuites. This issue affects OpenSSL 1.0.2 which is out of support and no longer receiving public updates. OpenSSL 1.1.1 is not vulnerable to this issue. Fixed in OpenSSL 1.0.2w (Affected 1.0.2-1.0.2v).
Affected products
-
- Version Fixed in OpenSSL 1.0.2w (Affected 1.0.2-1.0.2v)StatusaffectedConstraints-
- Version
Configuration 2
- 16.04
- 18.04
Configuration 3
- 9.0
Configuration 4
- a9.4
- 8.56
- 8.57
- 8.58
Configuration 5
- 2.0.0.14
Running on/with
- n/a
Configuration 6
- 2.0.0.14
Running on/with
- n/a
Configuration 7
- < xcp2400
Configuration 8
- < xcp2400
Configuration 9
- < xcp2400
Configuration 10
- < xcp2400
Configuration 11
- < xcp2400
Configuration 12
- < xcp2400
Configuration 13
- < xcp3100
Configuration 14
- < xcp3100
Configuration 15
- < xcp3100
Configuration 16
- < xcp3100
Configuration 17
- < xcp3100
Configuration 18
- < xcp3100
Configuration 19
- 1.3.1
Running on/with
- n/a
Configuration 20
- 1.2.2
Running on/with
- n/a
No data.
Red Hat Advanced Cluster Management for Kubernetes 2
openssl
Not affected
Red Hat Enterprise Linux 5
openssl
Out of support scope
Red Hat Enterprise Linux 5
openssl097a
Out of support scope
Red Hat Enterprise Linux 6
openssl
Out of support scope
Red Hat Enterprise Linux 6
openssl098e
Out of support scope
Red Hat Enterprise Linux 7
openssl
Fix deferred
Red Hat Enterprise Linux 7
openssl098e
Fix deferred
Red Hat Enterprise Linux 7
ovmf
Not affected
Red Hat Enterprise Linux 8
compat-openssl10
Fix deferred
Red Hat Enterprise Linux 8
mingw-openssl
Fix deferred
Red Hat Enterprise Linux 8
openssl
Not affected
Red Hat JBoss Core Services
jbcs-httpd24-openssl
Not affected
Red Hat JBoss Enterprise Application Platform 5
openssl
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
openssl
Out of support scope
Red Hat JBoss Enterprise Web Server 2
jbcs-httpd24-openssl
Out of support scope
Red Hat JBoss Enterprise Web Server 2
openssl
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Advanced Cluster Management for Kubernetes 2 | openssl | Not affected | n/a |
| Red Hat Enterprise Linux 5 | openssl | Out of support scope | n/a |
| Red Hat Enterprise Linux 5 | openssl097a | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | openssl | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | openssl098e | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | openssl | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | openssl098e | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | ovmf | Not affected | n/a |
| Red Hat Enterprise Linux 8 | compat-openssl10 | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | mingw-openssl | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | openssl | Not affected | n/a |
| Red Hat JBoss Core Services | jbcs-httpd24-openssl | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 5 | openssl | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | openssl | Out of support scope | n/a |
| Red Hat JBoss Enterprise Web Server 2 | jbcs-httpd24-openssl | Out of support scope | n/a |
| Red Hat JBoss Enterprise Web Server 2 | openssl | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
openssl 1.1.0i as bundled in the ovmf package shipped with Red Hat Enterprise Linux 7 supplementary rpms is not affected by this flaw. openssl 1.1.1 as shipped in Red Hat Enterprise Linux 8 is also not affected. Red Hat Advanced Cluster Management for Kubernetes does not use the vulnerable cipher suites, so it is not impacted by this flaw.
Red Hat mitigation
In OpenSSL 1.0.2e and below, this flaw can be mitigated by not enabling any ciphersuites with Diffie Hellman (DH), excluding ciphersuites using Elliptic Curve Diffie Hellman (ECDH). In OpenSSL 1.0.2f and above, this flaw can be mitigated by not enabling static DH ciphersuites. Such ciphersuites start with `DH-` in OpenSSL and are mapped to IANA names that start with `TLS_DH_`, excluding ciphersuites that start with `TLS_DH_anon`. Following this convention, we see that `DH-RSA-AES256-GCM-SHA384` with IANA name `TLS_DH_RSA_WITH_AES_256_GCM_SHA384` is affected and should not be used in a mitigation of this flaw. However, `ECDH-RSA-AES128-GCM-SHA256` with IANA name `TLS_ECDH_RSA_WITH_AES_128_GCM_SHA256` is not affected and may be used in a mitigation to this flaw, as it does not follow the `DH-` or `TLS_DH_` naming convention.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
1 other source (Red Hat) ▾
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:P/I:N/A:N
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Apr 16, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v5
Table of values (21 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 4.90% (0.04903) | 91.82th | v5 (v2026.06.15) |
| Jun 15, 2026 | 4.78% (0.04781) | 90.74th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.36% (0.00363) | 72.60th | v3 (v2023.03.01) |
| Jul 14, 2024 | 0.36% (0.00363) | 72.58th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.37% (0.00374) | 71.97th | v3 (v2023.03.01) |
| Nov 11, 2023 | 0.37% (0.00374) | 69.67th | v3 (v2023.03.01) |
| May 26, 2023 | 0.42% (0.00422) | 70.49th | v3 (v2023.03.01) |
| Apr 16, 2023 | 0.39% (0.00388) | 69.17th | v3 (v2023.03.01) |
| Mar 21, 2023 | 0.38% (0.00376) | 68.55th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.27% (0.00265) | 62.34th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.54% (0.01537) | 74.52th | v2 (v2022.01.01) |
| Apr 20, 2022 | 1.54% (0.01537) | 72.52th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.18% (0.01183) | 58.77th | v2 (v2022.01.01) |
| Feb 4, 2022 | 19.17% (0.19173) | 93.71th | v2 (v2022.01.01) |
| Feb 3, 2022 | 7.85% (0.07855) | 85.01th | v1 |
| Jan 6, 2022 | 7.85% (0.07855) | 84.84th | v1 |
| Oct 21, 2021 | 1.86% (0.01865) | 76.47th | v1 |
| Sep 1, 2021 | 1.66% (0.01659) | 73.96th | v1 |
| Jul 21, 2021 | 1.66% (0.01659) | 0.00th | v1 |
| Jun 15, 2021 | 1.45% (0.01454) | 0.00th | v1 |
| Apr 14, 2021 | 1.25% (0.01247) | 0.00th | v1 |
References (15)
- https://access.redhat.com/security/cve/CVE-2020-1968 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1877458 Issue Tracking
- https://lists.debian.org/debian-lts-announce/2020/09/msg00016.html mailing-listMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-1968
- https://raccoon-attack.com/RacoonAttack.pdf
- https://security.gentoo.org/glsa/202210-02 vendor-advisoryThird Party Advisory
- https://security.netapp.com/advisory/ntap-20200911-0004/ Third Party Advisory
- https://usn.ubuntu.com/4504-1/ vendor-advisoryThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-1968
- https://www.openssl.org/news/secadv/20200909.txt Vendor Advisory
- https://www.oracle.com//security-alerts/cpujul2021.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.html Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.html PatchThird Party Advisory
Change history (0)
No recorded changes yet.