CVE-2002-20001
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network bandwidth. The attack may be more disruptive in cases where a client can require a server to select its largest supported key size. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE.
Affected (64)
Products: Balasys: Dheater · Siemens: Scalance W1750d Firmware · Suse: Linux Enterprise Server · +3 more
Show all products
Balasys: Dheater · Siemens: Scalance W1750d Firmware · Suse: Linux Enterprise Server · F5: Big Ip Access Policy Manager, Big Ip Advanced Firewall Manager, Big Ip Advanced Web Application Firewall, Big Ip Analytics, Big Ip Application Acceleration Manager, Big Ip Application Security Manager, Big Ip Application Visibility And Reporting, Big Ip Carrier Grade Nat, Big Ip Ddos Hybrid Defender, Big Ip Domain Name System, Big Ip Edge Gateway, Big Ip Fraud Protection Service, Big Ip Global Traffic Manager, Big Ip Link Controller, Big Ip Local Traffic Manager, Big Ip Policy Enforcement Manager, Big Ip Service Proxy, Big Ip Ssl Orchestrator, Big Ip Webaccelerator, Big Ip Websafe, Big Iq Centralized Management, F5os A, F5os C, Traffix Signaling Delivery Controller · Hpe: Arubaos Cx · Stormshield: Stormshield Management Center, Stormshield Network Security
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance W1750d | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 13.1.0 to 16.1.4 | |
| From 13.1.0 to 17.1.2 | |
| From 13.1.0 to 17.1.2 | |
| From 13.1.0 to 17.1.2 | |
| From 13.1.0 to 17.1.2 | |
| From 13.1.0 to 17.1.2 | |
| From 13.1.0 to 17.1.2 | |
| From 13.1.0 to 17.1.2 | |
| From 13.1.0 to 17.1.2 | |
| From 13.1.0 to 17.1.2 | |
| From 13.1.0 to 17.1.2 | |
| From 13.1.0 to 17.1.2 | |
| From 13.1.0 to 17.1.2 | |
| From 13.1.0 to 17.1.2 | |
| From 13.1.0 to 17.1.2 | |
| From 13.1.0 to 17.1.2 | |
| Version 1.6.0 | |
| From 13.1.0 to 17.1.2 | |
| From 13.1.0 to 17.1.2 | |
| From 13.1.0 to 17.1.2 | |
| From 8.0.0 to 8.4.0 | |
| From 1.3.0 to 1.3.2 | |
| From 1.3.0 to 1.3.2 | |
| Version 5.1.0 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| From 10.06.0000 to 10.06.0180 |
| Running on/with | Platform Versions |
|---|---|
Hpe Aruba Cx 4100i | All versions |
Hpe Aruba Cx 6100 | All versions |
Hpe Aruba Cx 6200f | All versions |
Hpe Aruba Cx 6200m | All versions |
Hpe Aruba Cx 6300f | All versions |
Hpe Aruba Cx 6300m | All versions |
Hpe Aruba Cx 6405 | All versions |
Hpe Aruba Cx 6410 | All versions |
Hpe Aruba Cx 8320 | All versions |
Hpe Aruba Cx 8325 32c | All versions |
Hpe Aruba Cx 8325 48y8c | All versions |
Hpe Aruba Cx 8360 12c | All versions |
Hpe Aruba Cx 8360 16y2c | All versions |
Hpe Aruba Cx 8360 24xf2c | All versions |
Hpe Aruba Cx 8360 32y4c | All versions |
Hpe Aruba Cx 8360 48xt4c | All versions |
Hpe Aruba Cx 8360 48y6c | All versions |
Hpe Aruba Cx 8400 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.3.3 | |
| From 2.7.0 to 4.3.16 |
References (26)
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Technical DescriptionThird Party Advisory
Source: cve@mitre.org
Technical DescriptionThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Issue Tracking
Source: cve@mitre.org
ExploitTechnical Description
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ProductThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Technical DescriptionThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Technical DescriptionThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitTechnical Description
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.