
Cloud Vulnerability DB
A community-led vulnerabilities database
The Raccoon attack (CVE-2020-1968) is a vulnerability in the TLS specification discovered in September 2020. The vulnerability affects Diffie-Hellman (DH) based ciphersuites and can allow an attacker to compute the pre-master secret in TLS connections, potentially leading to eavesdropping on encrypted communications. The vulnerability specifically impacts implementations that re-use DH secrets across multiple TLS connections, and only affects DH ciphersuites, not ECDH ciphersuites (OpenSSL Advisory).
The vulnerability has a CVSS v3.1 Base Score of 3.7 (LOW) with vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N. The attack exploits a flaw in the TLS specification related to how Diffie-Hellman secrets are handled. It can only be exploited if an implementation reuses a DH secret across multiple TLS connections. The vulnerability affects OpenSSL versions 1.0.2 through 1.0.2v but does not impact version 1.1.1 (NVD).
If successfully exploited, the vulnerability would allow an attacker to eavesdrop on all encrypted communications sent over the affected TLS connection by computing the pre-master secret. This could lead to disclosure of sensitive information transmitted over what should be secure connections (OpenSSL Advisory).
The vulnerability requires high attack complexity and can only be exploited if an implementation reuses DH secrets across multiple TLS connections. It specifically impacts DH ciphersuites but not ECDH ciphersuites. OpenSSL 1.1.1 is not vulnerable as it never reuses DH secrets (OpenSSL Advisory).
For OpenSSL 1.0.2, the vulnerability was fixed in version 1.0.2w. For affected versions, users should ensure that DH ciphersuites are disabled through runtime configuration. The vulnerability can also be mitigated by not reusing DH secrets across TLS connections. For Clustered Data ONTAP users, DH ciphers can be manually disabled using the 'security config' command (NetApp Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."