Raccoon attack in OpenSSL - CVE-2020-1968
Published: September 10, 2020 / Updated: October 30, 2023
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a timing flaw in the TLS specification. A remote attacker can compute the pre-master secret in connections which have used a Diffie-Hellman (DH) based ciphersuite and eavesdrop on all encrypted communications sent over that TLS connection.
Note: The attack can only be exploited if an implementation re-uses a DH secret across multiple TLS connections.
Affected software
Gentoo Linux
IBM AIX
Palo Alto PAN-OS
Oracle Solaris
Ubuntu
Junos OS
MicroSCADA Pro SYS600
MicroSCADA X SYS600
Gateway Station (GWS)
FACTS Control Platform (FCP)
SDM600
Telemetry Dashboard
Liquidware
Citrix Workspace App
Webex App VDI
Oracle Ethernet Switch TOR-72
Oracle Ethernet Switch ES1-24
IBM Rational Build Forge
IBM Safer Payments
Engineering Workflow Management
NetWorker
Prisma Access
BIG-IP Advanced WAF
IBM VIOS
IBM Qradar SIEM
PeopleSoft Enterprise PeopleTools
RTU500 CMU
BIG-IP
BIG-IP DDHD
BIG-IP SSLO
BIG-IP Analytics
BIG-IP AFM
BIG-IP APM
BIG-IP ASM
BIG-IP PEM
BIG-IP LTM
BIG-IP FPS
BIG-IP GTM
BIG-IP DNS
BIG-IP AAM
BIG-IP Link Controller
Cisco Jabber
Cisco Webex Meetings
VMware Horizon Client
openssl (Ubuntu package)
libssl1.0.0 (Ubuntu package)
dev-libs/openssl
Engineering Lifecycle Management
How to mitigate CVE-2020-1968
MicroSCADA Pro SYS600 - update to 10.3
MicroSCADA X SYS600 - update to 10.3
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
Prisma Access - update to 2.2.0
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
IBM Qradar SIEM - update to 7.5.0 Update Pack 8
IBM Rational Build Forge - update to 8.0.0.24
Palo Alto PAN-OS - update to 10.0.0
RTU500 CMU - addressed in versions 12.0.14.0, 12.2.11.0, 12.4.11, 12.6.7, 12.7.2, 13.2.3
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Junos OS - addressed in versions 18.4R2-S10, 19.2R1-S9, 19.2R3-S5, 19.3R3-S5, 19.4R3-S7, 20.1R3-S3, 20.2R3-S4, 20.3R3-S2, 20.4R3-S1, 21.1R3-S1, 21.2R2-S1, 21.2R3, 21.3R2, 21.4R1
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
openssl (Ubuntu package) - update to Ubuntu Pro
libssl1.0.0 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.0.2g-1ubuntu4.17, 1.0.2n-1ubuntu5.4
dev-libs/openssl - update to 1.1.1q
SDM600 - update to 1.2 FP2 HF10
IBM Safer Payments - addressed in versions 5.7.0.13, 6.0.0.10
Engineering Lifecycle Management - addressed in versions 7.0.1 iFix022, 7.0.2 iFix023
Engineering Workflow Management - addressed in versions 7.0.1 iFix022, 7.0.2 iFix023
NetWorker - update to 19.10.0.0
External References
Related Security Bulletins
- Raccoon attack in OpenSSL
- Raccoon attack against TLS implementation in F5 BIG-IP
- Multiple vulnerabilities in PeopleSoft Enterprise PeopleTools
- Multiple vulnerabilities in Oracle Solaris
- IBM AIX update for OpenSSL
- IBM VIOS update for OpenSSL
- Raccoon Attack in Palo Alto Networks PAN-OS
- Raccoon Attack in Palo Alto Prisma Access
- Multiple vulnerabilities in Hitachi Energy RTU500 series CMU
- Multiple vulnerabilities in Hitachi Energy MicroSCADA Pro/X SYS600
- Raccoon attack in Oracle Ethernet Switch TOR-72
- Raccoon attack in Oracle Ethernet Switch ES1-24
- Multiple vulnerabilities in Hitachi Energy SDM600
- Junos OS update for OpenSSL
- Multiple vulnerabilities in Hitachi Energy FACTS Control Platform (FCP)
- Multiple vulnerabilities in Hitachi Energy Gateway Station (GWS)
- Gentoo update for OpenSSL
- Raccoon attack in IBM Safer Payment
- Raccoon attack in IBM Engineering Workflow Management (EWM)
- Multiple vulnerabilities in IBM Rational Build Forge
- Multiple vulnerabilities in Dell Networker
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Dell ThinOS
- Ubuntu update for openssl
- Ubuntu update for openssl