PT-2020-5492 · Openssl+4 · Openssl+4

Published

2020-09-09

·

Updated

2024-09-18

·

CVE-2020-1968

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenSSL versions 1.0.2 through 1.0.2v PAN-OS software versions earlier than 10.0
Description The issue is related to a flaw in the TLS specification that can lead to an attacker being able to compute the pre-master secret in connections which have used a Diffie-Hellman (DH) based ciphersuite. This would result in the attacker being able to eavesdrop on all encrypted communications sent over that TLS connection. The attack can only be exploited if an implementation re-uses a DH secret across multiple TLS connections. Note that this issue only impacts DH ciphersuites and not ECDH ciphersuites.
Recommendations For OpenSSL versions 1.0.2 through 1.0.2v, update to version 1.0.2w to fix the issue. For PAN-OS software versions earlier than 10.0, update to version 10.0 or later to fix the issue. As a temporary workaround, consider disabling the use of DH ciphersuites in TLS connections until a patch is available. Restrict access to the affected components, such as SSL Forward-Proxy, SSL Inbound Inspection, GlobalProtect Portal, GlobalProtect Gateway, and GlobalProtect Clientless VPN, to minimize the risk of exploitation.

Exploit

Fix

Side Channel Attack

Inadequate Encryption Strength

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-00873
CVE-2020-1968
DLA-2378-1
MGASA-2020-0465
SUSE-SU-2020:14491-1
SUSE-SU-2020:14511-1
SUSE-SU-2020:2634-1
SUSE-SU-2020_14491-1
SUSE-SU-2020_14511-1
USN-4504-1
USN-7018-1

Affected Products

Astra Linux
Openssl
Pan-Os
Suse
Ubuntu