HIGH · 7.5

CVE-2002-20001

The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-expo...

Vulnerability Description

The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network bandwidth. The attack may be more disruptive in cases where a client can require a server to select its largest supported key size. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
BalasysDheater-
SiemensScalance W1750D FirmwareAll versions
SiemensScalance W1750D-
SuseLinux Enterprise Server11
F5Big-Ip Access Policy Manager>= 13.1.0, < 16.1.4
F5Big-Ip Advanced Firewall Manager>= 13.1.0, <= 17.1.2
F5Big-Ip Advanced Web Application Firewall>= 13.1.0, <= 17.1.2
F5Big-Ip Analytics>= 13.1.0, <= 17.1.2
F5Big-Ip Application Acceleration Manager>= 13.1.0, <= 17.1.2
F5Big-Ip Application Security Manager>= 13.1.0, <= 17.1.2
F5Big-Ip Application Visibility And Reporting>= 13.1.0, <= 17.1.2
F5Big-Ip Carrier-Grade Nat>= 13.1.0, <= 17.1.2
F5Big-Ip Ddos Hybrid Defender>= 13.1.0, <= 17.1.2
F5Big-Ip Domain Name System>= 13.1.0, <= 17.1.2
F5Big-Ip Edge Gateway>= 13.1.0, <= 17.1.2
F5Big-Ip Fraud Protection Service>= 13.1.0, <= 17.1.2
F5Big-Ip Global Traffic Manager>= 13.1.0, <= 17.1.2
F5Big-Ip Link Controller>= 13.1.0, <= 17.1.2
F5Big-Ip Local Traffic Manager>= 13.1.0, <= 17.1.2
F5Big-Ip Policy Enforcement Manager>= 13.1.0, <= 17.1.2

Related Weaknesses (CWE)

References

FAQ

What is CVE-2002-20001?

CVE-2002-20001 is a vulnerability with a CVSS score of 7.5 (HIGH). The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-expo...

How severe is CVE-2002-20001?

CVE-2002-20001 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2002-20001?

Check the references section above for vendor advisories and patch information. Affected products include: Balasys Dheater, Siemens Scalance W1750D Firmware, Siemens Scalance W1750D, Suse Linux Enterprise Server, F5 Big-Ip Access Policy Manager.