CVE-2020-1968
OpenSSL vulnerability analysis and mitigation

Overview

The Raccoon attack (CVE-2020-1968) is a vulnerability in the TLS specification discovered in September 2020. The vulnerability affects Diffie-Hellman (DH) based ciphersuites and can allow an attacker to compute the pre-master secret in TLS connections, potentially leading to eavesdropping on encrypted communications. The vulnerability specifically impacts implementations that re-use DH secrets across multiple TLS connections, and only affects DH ciphersuites, not ECDH ciphersuites (OpenSSL Advisory).

Technical details

The vulnerability has a CVSS v3.1 Base Score of 3.7 (LOW) with vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N. The attack exploits a flaw in the TLS specification related to how Diffie-Hellman secrets are handled. It can only be exploited if an implementation reuses a DH secret across multiple TLS connections. The vulnerability affects OpenSSL versions 1.0.2 through 1.0.2v but does not impact version 1.1.1 (NVD).

Impact

If successfully exploited, the vulnerability would allow an attacker to eavesdrop on all encrypted communications sent over the affected TLS connection by computing the pre-master secret. This could lead to disclosure of sensitive information transmitted over what should be secure connections (OpenSSL Advisory).

Exploitability

The vulnerability requires high attack complexity and can only be exploited if an implementation reuses DH secrets across multiple TLS connections. It specifically impacts DH ciphersuites but not ECDH ciphersuites. OpenSSL 1.1.1 is not vulnerable as it never reuses DH secrets (OpenSSL Advisory).

Mitigation and workarounds

For OpenSSL 1.0.2, the vulnerability was fixed in version 1.0.2w. For affected versions, users should ensure that DH ciphersuites are disabled through runtime configuration. The vulnerability can also be mitigated by not reusing DH secrets across TLS connections. For Clustered Data ONTAP users, DH ciphers can be manually disabled using the 'security config' command (NetApp Advisory).

Additional resources


SourceThis report was generated using AI

Related OpenSSL vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-63073CRITICAL9.8
  • OpenSSL logoOpenSSL
  • openssl.src
NoYesAug 25, 2026
CVE-2026-63076HIGH7.5
  • OpenSSL logoOpenSSL
  • openssl-devel
NoYesAug 25, 2026
CVE-2026-63075HIGH7.5
  • OpenSSL logoOpenSSL
  • openssl-3-doc
NoYesAug 25, 2026
CVE-2026-63072HIGH7.5
  • OpenSSL logoOpenSSL
  • openssl-3.0
NoYesAug 25, 2026
CVE-2026-63074MEDIUM5.9
  • OpenSSL logoOpenSSL
  • cpe:2.3:a:openssl:openssl
NoYesAug 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management