PT-2020-5492 · Openssl+4 · Openssl+4
Published
2020-09-09
·
Updated
2024-09-18
·
CVE-2020-1968
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenSSL versions 1.0.2 through 1.0.2v
PAN-OS software versions earlier than 10.0
Description
The issue is related to a flaw in the TLS specification that can lead to an attacker being able to compute the pre-master secret in connections which have used a Diffie-Hellman (DH) based ciphersuite. This would result in the attacker being able to eavesdrop on all encrypted communications sent over that TLS connection. The attack can only be exploited if an implementation re-uses a DH secret across multiple TLS connections. Note that this issue only impacts DH ciphersuites and not ECDH ciphersuites.
Recommendations
For OpenSSL versions 1.0.2 through 1.0.2v, update to version 1.0.2w to fix the issue.
For PAN-OS software versions earlier than 10.0, update to version 10.0 or later to fix the issue.
As a temporary workaround, consider disabling the use of DH ciphersuites in TLS connections until a patch is available.
Restrict access to the affected components, such as SSL Forward-Proxy, SSL Inbound Inspection, GlobalProtect Portal, GlobalProtect Gateway, and GlobalProtect Clientless VPN, to minimize the risk of exploitation.
Exploit
Fix
Side Channel Attack
Inadequate Encryption Strength
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Openssl
Pan-Os
Suse
Ubuntu