CVE-2002-20001

T

he Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network bandwidth. The attack may be more disruptive in cases where a client can require a server to select its largest supported key size. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE.

References
Link Resource
https://cert-portal.siemens.com/productcert/pdf/ssa-506569.pdf Third Party Advisory
https://dheatattack.com Third Party Advisory
https://dheatattack.gitlab.io/ Third Party Advisory
https://github.com/Balasys/dheater Product Third Party Advisory
https://github.com/mozilla/ssl-config-generator/issues/162 Issue Tracking
https://gitlab.com/dheatattack/dheater Third Party Advisory
https://ieeexplore.ieee.org/document/10374117 Technical Description Third Party Advisory
https://support.f5.com/csp/article/K83120834 Third Party Advisory
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-004.txt Third Party Advisory Technical Description
https://www.openssl.org/blog/blog/2022/10/21/tls-groups-configuration/ Third Party Advisory
https://www.reddit.com/r/netsec/comments/qdoosy/server_overload_by_enforcing_dhe_key_exchange/ Issue Tracking
https://www.researchgate.net/profile/Anton-Stiglic-2/publication/2401745_Security_Issues_in_the_Diffie-Hellman_Key_Agreement_Protocol Exploit Technical Description
https://www.suse.com/support/kb/doc/?id=000020510 Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-506569.pdf Third Party Advisory
https://dheatattack.com Third Party Advisory
https://dheatattack.gitlab.io/ Third Party Advisory
https://github.com/Balasys/dheater Product Third Party Advisory
https://github.com/mozilla/ssl-config-generator/issues/162 Issue Tracking
https://gitlab.com/dheatattack/dheater Third Party Advisory
https://ieeexplore.ieee.org/document/10374117 Technical Description Third Party Advisory
https://support.f5.com/csp/article/K83120834 Third Party Advisory
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-004.txt Third Party Advisory Technical Description
https://www.openssl.org/blog/blog/2022/10/21/tls-groups-configuration/ Third Party Advisory
https://www.reddit.com/r/netsec/comments/qdoosy/server_overload_by_enforcing_dhe_key_exchange/ Issue Tracking
https://www.researchgate.net/profile/Anton-Stiglic-2/publication/2401745_Security_Issues_in_the_Diffie-Hellman_Key_Agreement_Protocol Exploit Technical Description
https://www.suse.com/support/kb/doc/?id=000020510 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:balasys:dheater:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:siemens:scalance_w1750d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_w1750d:-:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:suse:linux_enterprise_server:11:-:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:12:-:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:15:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:17.5.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:17.5.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_analytics:17.5.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_application_acceleration_manager:17.5.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_application_security_manager:17.5.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_application_visibility_and_reporting:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_application_visibility_and_reporting:17.5.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_carrier-grade_nat:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_carrier-grade_nat:17.5.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:17.5.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_domain_name_system:17.5.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_edge_gateway:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_edge_gateway:17.5.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_fraud_protection_service:17.5.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_global_traffic_manager:17.5.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_link_controller:17.5.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_local_traffic_manager:17.5.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:17.5.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_service_proxy:1.6.0:*:*:*:*:kubernetes:*:*
cpe:2.3:a:f5:big-ip_ssl_orchestrator:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_ssl_orchestrator:17.5.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_webaccelerator:17.5.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_websafe:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_websafe:17.5.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-iq_centralized_management:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-iq_centralized_management:7.1.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:traffix_signaling_delivery_controller:5.1.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:traffix_signaling_delivery_controller:5.2.0:*:*:*:*:*:*:*
cpe:2.3:o:f5:f5os-a:*:*:*:*:*:*:*:*
cpe:2.3:o:f5:f5os-a:*:*:*:*:*:*:*:*
cpe:2.3:o:f5:f5os-a:1.8.0:*:*:*:*:*:*:*
cpe:2.3:o:f5:f5os-c:*:*:*:*:*:*:*:*
cpe:2.3:o:f5:f5os-c:*:*:*:*:*:*:*:*
cpe:2.3:o:f5:f5os-c:1.5.0:*:*:*:*:*:*:*
cpe:2.3:o:f5:f5os-c:1.5.1:*:*:*:*:*:*:*
cpe:2.3:o:f5:f5os-c:1.8.0:*:*:*:*:*:*:*
cpe:2.3:o:f5:f5os-c:1.8.1:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
OR cpe:2.3:o:hpe:arubaos-cx:*:*:*:*:*:*:*:*
cpe:2.3:o:hpe:arubaos-cx:*:*:*:*:*:*:*:*
cpe:2.3:o:hpe:arubaos-cx:*:*:*:*:*:*:*:*
cpe:2.3:o:hpe:arubaos-cx:*:*:*:*:*:*:*:*
OR cpe:2.3:h:hpe:aruba_cx_4100i:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6100:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6200f:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6200m:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6300f:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6300m:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6405:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6410:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_8320:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_8325-32c:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_8325-48y8c:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_8360-12c:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_8360-16y2c:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_8360-24xf2c:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_8360-32y4c:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_8360-48xt4c:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_8360-48y6c:-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_8400:-:*:*:*:*:*:*:*

Configuration 6 (hide)

OR cpe:2.3:a:stormshield:stormshield_management_center:*:*:*:*:*:*:*:*
cpe:2.3:a:stormshield:stormshield_network_security:*:*:*:*:*:*:*:*
cpe:2.3:a:stormshield:stormshield_network_security:*:*:*:*:*:*:*:*

History

22 Aug 2025, 10:33

Type Values Removed Values Added
References () https://dheatattack.gitlab.io/ - () https://dheatattack.gitlab.io/ - Third Party Advisory
References () https://github.com/Balasys/dheater - Product () https://github.com/Balasys/dheater - Product, Third Party Advisory
References () https://gitlab.com/dheatattack/dheater - () https://gitlab.com/dheatattack/dheater - Third Party Advisory
References () https://ieeexplore.ieee.org/document/10374117 - () https://ieeexplore.ieee.org/document/10374117 - Technical Description, Third Party Advisory
References () https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-004.txt - Third Party Advisory () https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-004.txt - Third Party Advisory, Technical Description
CPE cpe:2.3:o:f5:f5os-a:1.3.0:*:*:*:*:*:*:*
cpe:2.3:o:f5:f5os-a:1.3.1:*:*:*:*:*:*:*
cpe:2.3:o:f5:f5os-c:1.8.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_carrier-grade_nat:17.5.0:*:*:*:*:*:*:*
cpe:2.3:o:f5:f5os-a:1.8.0:*:*:*:*:*:*:*
cpe:2.3:o:f5:f5os-a:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_application_acceleration_manager:17.5.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_application_visibility_and_reporting:17.5.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_global_traffic_manager:17.5.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_link_controller:17.5.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:17.5.0:*:*:*:*:*:*:*
cpe:2.3:o:f5:f5os-c:1.8.1:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_fraud_protection_service:17.5.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:17.5.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_domain_name_system:17.5.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_edge_gateway:17.5.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_ssl_orchestrator:17.5.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_application_security_manager:17.5.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:17.5.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:17.5.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_websafe:17.5.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_analytics:17.5.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_webaccelerator:17.5.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_local_traffic_manager:17.5.0:*:*:*:*:*:*:*

15 Apr 2025, 14:08

Type Values Removed Values Added
CPE cpe:2.3:a:f5:f5os-a:1.3.1:*:*:*:*:*:*:*
cpe:2.3:a:f5:f5os-c:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:f5os-a:1.3.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:f5os-c:1.5.1:*:*:*:*:*:*:*
cpe:2.3:a:f5:f5os-c:1.5.0:*:*:*:*:*:*:*
cpe:2.3:o:f5:f5os-c:1.5.1:*:*:*:*:*:*:*
cpe:2.3:o:f5:f5os-a:1.3.0:*:*:*:*:*:*:*
cpe:2.3:o:f5:f5os-c:*:*:*:*:*:*:*:*
cpe:2.3:o:f5:f5os-c:1.5.0:*:*:*:*:*:*:*
cpe:2.3:o:f5:f5os-a:1.3.1:*:*:*:*:*:*:*

20 Nov 2024, 23:42

Type Values Removed Values Added
References () https://cert-portal.siemens.com/productcert/pdf/ssa-506569.pdf - Third Party Advisory () https://cert-portal.siemens.com/productcert/pdf/ssa-506569.pdf - Third Party Advisory
References () https://dheatattack.com - Third Party Advisory () https://dheatattack.com - Third Party Advisory
References () https://dheatattack.gitlab.io/ - () https://dheatattack.gitlab.io/ -
References () https://github.com/Balasys/dheater - Product () https://github.com/Balasys/dheater - Product
References () https://github.com/mozilla/ssl-config-generator/issues/162 - Issue Tracking () https://github.com/mozilla/ssl-config-generator/issues/162 - Issue Tracking
References () https://gitlab.com/dheatattack/dheater - () https://gitlab.com/dheatattack/dheater -
References () https://ieeexplore.ieee.org/document/10374117 - () https://ieeexplore.ieee.org/document/10374117 -
References () https://support.f5.com/csp/article/K83120834 - Third Party Advisory () https://support.f5.com/csp/article/K83120834 - Third Party Advisory
References () https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-004.txt - Third Party Advisory () https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-004.txt - Third Party Advisory
References () https://www.openssl.org/blog/blog/2022/10/21/tls-groups-configuration/ - Third Party Advisory () https://www.openssl.org/blog/blog/2022/10/21/tls-groups-configuration/ - Third Party Advisory
References () https://www.reddit.com/r/netsec/comments/qdoosy/server_overload_by_enforcing_dhe_key_exchange/ - Issue Tracking () https://www.reddit.com/r/netsec/comments/qdoosy/server_overload_by_enforcing_dhe_key_exchange/ - Issue Tracking
References () https://www.researchgate.net/profile/Anton-Stiglic-2/publication/2401745_Security_Issues_in_the_Diffie-Hellman_Key_Agreement_Protocol - Exploit, Technical Description () https://www.researchgate.net/profile/Anton-Stiglic-2/publication/2401745_Security_Issues_in_the_Diffie-Hellman_Key_Agreement_Protocol - Exploit, Technical Description
References () https://www.suse.com/support/kb/doc/?id=000020510 - Third Party Advisory () https://www.suse.com/support/kb/doc/?id=000020510 - Third Party Advisory