Get real-time updates on Telegram
CVE-2020-1967: openssl from 1.1.1d (inclusive), through 1.1.1f (inclusive); +26 more affected products
CVE-2020-1967. CVSS 3.1 base score 7.5 (HIGH, NVD). EPSS 0.53336 (percentile 0.98962), scored 2026-10-08.
Affected technology
openssl · from 1.1.1d (inclusive), through 1.1.1f (inclusive)
openssl
debian linux · 9.0
debian
debian linux · 10.0
debian
freebsd · 12.1
freebsd
fedora · 30
fedoraproject
fedora · 31
fedoraproject
fedora · 32
fedoraproject
application server · 12.1.3
oracle
enterprise manager base platform · 13.4.0.0
oracle
enterprise manager for storage management · 13.3.0.0
oracle
enterprise manager for storage management · 13.4.0.0
oracle
enterprise manager ops center · 12.4.0
oracle
http server · 12.2.1.4.0
oracle
jd edwards world security · a9.4
oracle
mysql · through 5.6.48 (inclusive)
oracle
mysql · from 5.7.0 (inclusive), through 5.7.30 (inclusive)
oracle
mysql · from 8.0.0 (inclusive), through 8.0.20 (inclusive)
oracle
mysql connectors · through 8.0.20 (inclusive)
oracle
mysql enterprise monitor · through 4.0.12 (inclusive)
oracle
mysql enterprise monitor · from 8.0.0 (inclusive), through 8.0.20 (inclusive)
oracle
mysql workbench · through 8.0.21 (inclusive)
oracle
peoplesoft enterprise peopletools · 8.56
oracle
peoplesoft enterprise peopletools · 8.57
oracle
peoplesoft enterprise peopletools · 8.58
oracle
peoplesoft enterprise peopletools · 8.59
oracle
active iq unified manager · from 7.3 (inclusive)
netapp
active iq unified manager · from 9.5 (inclusive)
netapp
e-series performance analyzer · Version not applicable in the source CPE
netapp
oncommand insight · Version not applicable in the source CPE
netapp
oncommand workflow automation · Version not applicable in the source CPE
netapp
smi-s provider · Version not applicable in the source CPE
netapp
snapcenter · Version not applicable in the source CPE
netapp
steelstore cloud integrated storage · Version not applicable in the source CPE
netapp
fabric operating system · Version not applicable in the source CPE
broadcom
leap · 15.1
opensuse
leap · 15.2
opensuse
enterpriseone · before 9.2.5.0 (exclusive)
jdedwards
log correlation engine · before 6.0.9 (exclusive)
tenable
OpenSSL · Fixed in OpenSSL 1.1.1g (Affected 1.1.1d-1.1.1f)
OpenSSL
Component: Not specified by the source
Function: during
Attack conditions (NVD, CVSS 3.1): Network (remote) · No privileges required · No user interaction required
What an attacker can do
The source reports that an attacker could disrupt service under the conditions described by the source. NVD’s CVSS 3.1 assessment (base score 7.5/10) rates confidentiality and integrity impact as none; availability impact as high.
- CWE
- CWE-476
- CCR priority
- 43.3 /100 (P3)
- CVSS 3.1
- 7.5 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H · NVD
- EPSS
- 0.53336 · percentile 0.98962 · 2026-10-08
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-09 03:13:32.966430+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2020-1967.html