CYBER CODE RED

Get real-time updates on Telegram

P3Verified

CVE-2020-1967: openssl from 1.1.1d (inclusive), through 1.1.1f (inclusive); +26 more affected products

CVE-2020-1967. CVSS 3.1 base score 7.5 (HIGH, NVD). EPSS 0.53336 (percentile 0.98962), scored 2026-10-08.

Affected technology

openssl · from 1.1.1d (inclusive), through 1.1.1f (inclusive)
openssl

debian linux · 9.0
debian

debian linux · 10.0
debian

freebsd · 12.1
freebsd

fedora · 30
fedoraproject

fedora · 31
fedoraproject

fedora · 32
fedoraproject

application server · 12.1.3
oracle

enterprise manager base platform · 13.4.0.0
oracle

enterprise manager for storage management · 13.3.0.0
oracle

enterprise manager for storage management · 13.4.0.0
oracle

enterprise manager ops center · 12.4.0
oracle

http server · 12.2.1.4.0
oracle

jd edwards world security · a9.4
oracle

mysql · through 5.6.48 (inclusive)
oracle

mysql · from 5.7.0 (inclusive), through 5.7.30 (inclusive)
oracle

mysql · from 8.0.0 (inclusive), through 8.0.20 (inclusive)
oracle

mysql connectors · through 8.0.20 (inclusive)
oracle

mysql enterprise monitor · through 4.0.12 (inclusive)
oracle

mysql enterprise monitor · from 8.0.0 (inclusive), through 8.0.20 (inclusive)
oracle

mysql workbench · through 8.0.21 (inclusive)
oracle

peoplesoft enterprise peopletools · 8.56
oracle

peoplesoft enterprise peopletools · 8.57
oracle

peoplesoft enterprise peopletools · 8.58
oracle

peoplesoft enterprise peopletools · 8.59
oracle

active iq unified manager · from 7.3 (inclusive)
netapp

active iq unified manager · from 9.5 (inclusive)
netapp

e-series performance analyzer · Version not applicable in the source CPE
netapp

oncommand insight · Version not applicable in the source CPE
netapp

oncommand workflow automation · Version not applicable in the source CPE
netapp

smi-s provider · Version not applicable in the source CPE
netapp

snapcenter · Version not applicable in the source CPE
netapp

steelstore cloud integrated storage · Version not applicable in the source CPE
netapp

fabric operating system · Version not applicable in the source CPE
broadcom

leap · 15.1
opensuse

leap · 15.2
opensuse

enterpriseone · before 9.2.5.0 (exclusive)
jdedwards

log correlation engine · before 6.0.9 (exclusive)
tenable

OpenSSL · Fixed in OpenSSL 1.1.1g (Affected 1.1.1d-1.1.1f)
OpenSSL

Component: Not specified by the source
Function: during

Attack conditions (NVD, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

The source reports that an attacker could disrupt service under the conditions described by the source. NVD’s CVSS 3.1 assessment (base score 7.5/10) rates confidentiality and integrity impact as none; availability impact as high.

Published

CWE
CWE-476
CCR priority
43.3 /100 (P3)
CVSS 3.1
7.5 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H · NVD
EPSS
0.53336 · percentile 0.98962 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2020-1967.html