← Back

CVE-2002-20001

nvd nist
Published: Nov 11, 2021Modified: Aug 22, 2025

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network bandwidth. The attack may be more disruptive in cases where a client can require a server to select its largest supported key size. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE.

Affected (64)

Show all products
1 product
Dheater
1 product
Scalance W1750d Firmware
1 product
Linux Enterprise Server
24 products
Big Ip Access Policy Manager
Big Ip Advanced Firewall Manager
Big Ip Analytics
Big Ip Carrier Grade Nat
Big Ip Ddos Hybrid Defender
Big Ip Domain Name System
Big Ip Edge Gateway
Big Ip Fraud Protection Service
Big Ip Global Traffic Manager
Big Ip Link Controller
Big Ip Local Traffic Manager
Big Ip Policy Enforcement Manager
Big Ip Service Proxy
Big Ip Ssl Orchestrator
Big Ip Webaccelerator
Big Ip Websafe
Big Iq Centralized Management
F5os A
F5os C
1 product
Arubaos Cx
2 products
Stormshield Management Center
Stormshield Network Security
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Scalance W1750d
All versions
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Suse
Version 11
Version 12
Version 15
Configuration D
52 vulnerable
Vulnerable SoftwareAffected Versions
F5
From 13.1.0 to 16.1.4
From 17.0.0 to 17.1.0
F5
From 13.1.0 to 17.1.2
Version 17.5.0
F5
From 13.1.0 to 17.1.2
Version 17.5.0
F5
From 13.1.0 to 17.1.2
Version 17.5.0
F5
From 13.1.0 to 17.1.2
Version 17.5.0
F5
From 13.1.0 to 17.1.2
Version 17.5.0
F5
From 13.1.0 to 17.1.2
Version 17.5.0
F5
From 13.1.0 to 17.1.2
Version 17.5.0
F5
From 13.1.0 to 17.1.2
Version 17.5.0
F5
From 13.1.0 to 17.1.2
Version 17.5.0
F5
From 13.1.0 to 17.1.2
Version 17.5.0
F5
From 13.1.0 to 17.1.2
Version 17.5.0
F5
From 13.1.0 to 17.1.2
Version 17.5.0
F5
From 13.1.0 to 17.1.2
Version 17.5.0
F5
From 13.1.0 to 17.1.2
Version 17.5.0
F5
From 13.1.0 to 17.1.2
Version 17.5.0
Version 1.6.0
F5
From 13.1.0 to 17.1.2
Version 17.5.0
F5
From 13.1.0 to 17.1.2
Version 17.5.0
F5
From 13.1.0 to 17.1.2
Version 17.5.0
F5
From 8.0.0 to 8.4.0
Version 7.1.0
F5
From 1.3.0 to 1.3.2
From 1.5.0 to 1.5.3
Version 1.8.0
F5
From 1.3.0 to 1.3.2
From 1.6.0 to 1.6.2
Version 1.5.0
Version 1.5.1
Version 1.8.0
Version 1.8.1
F5
Version 5.1.0
Version 5.2.0
Configuration E
4 vulnerable · 18 platform
Vulnerable SoftwareAffected Versions
Hpe
From 10.06.0000 to 10.06.0180
From 10.07.0000 to 10.07.0030
From 10.08.0000 to 10.08.0010
From 10.09.0000 to 10.09.0002
Running on/withPlatform Versions
Hpe
Aruba Cx 4100i
All versions
Hpe
Aruba Cx 6100
All versions
Hpe
Aruba Cx 6200f
All versions
Hpe
Aruba Cx 6200m
All versions
Hpe
Aruba Cx 6300f
All versions
Hpe
Aruba Cx 6300m
All versions
Hpe
Aruba Cx 6405
All versions
Hpe
Aruba Cx 6410
All versions
Hpe
Aruba Cx 8320
All versions
Hpe
Aruba Cx 8325 32c
All versions
Hpe
Aruba Cx 8325 48y8c
All versions
Hpe
Aruba Cx 8360 12c
All versions
Hpe
Aruba Cx 8360 16y2c
All versions
Hpe
Aruba Cx 8360 24xf2c
All versions
Hpe
Aruba Cx 8360 32y4c
All versions
Hpe
Aruba Cx 8360 48xt4c
All versions
Hpe
Aruba Cx 8360 48y6c
All versions
Hpe
Aruba Cx 8400
All versions
Configuration F
3 vulnerable
Vulnerable SoftwareAffected Versions
Before 3.3.3
Stormshield
From 2.7.0 to 4.3.16
From 4.4.0 to 4.6.3

References (26)

Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
ProductThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Technical DescriptionThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Technical DescriptionThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ProductThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Technical DescriptionThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Technical DescriptionThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.