Vulnerability centers around the now-obsolete protocol SSLv2, a 1990s-era predecessor to TLS. The vulnerability can enable the attacker to decrypt the connections between up-to-date clients and servers. Using the same security certificate on two different servers means they will share the same private key. An attacker can find the key of the email server via DROWN and then use it to decrypt the HTTPS connections to the Web server. An Internet scan showed that more than 2.3 million HTTPS servers with browser-trusted certificates are vulnerable to DROWN.”]
Source: https://securityintelligence.com/news/openssl-can-be-drowned-by-new-vulnerability/

