7.5

CVE-2002-20001

Exploit

The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network bandwidth. The attack may be more disruptive in cases where a client can require a server to select its largest supported key size. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
BalasysDheater Version-
SuseLinux Enterprise Server Version11 Update-
SuseLinux Enterprise Server Version12 Update-
F5Big-ip Access Policy Manager Version >= 13.1.0 < 16.1.4
F5Big-ip Access Policy Manager Version >= 17.0.0 < 17.1.0
F5Big-ip Advanced Firewall Manager Version >= 13.1.0 <= 17.1.2
F5Big-ip Advanced Web Application Firewall Version >= 13.1.0 <= 17.1.2
F5Big-ip Analytics Version >= 13.1.0 <= 17.1.2
F5Big-ip Analytics Version17.5.0
F5Big-ip Application Acceleration Manager Version >= 13.1.0 <= 17.1.2
F5Big-ip Application Security Manager Version >= 13.1.0 <= 17.1.2
F5Big-ip Application Visibility And Reporting Version >= 13.1.0 <= 17.1.2
F5Big-ip Carrier-grade Nat Version >= 13.1.0 <= 17.1.2
F5Big-ip Carrier-grade Nat Version17.5.0
F5Big-ip Ddos Hybrid Defender Version >= 13.1.0 <= 17.1.2
F5Big-ip Ddos Hybrid Defender Version17.5.0
F5Big-ip Domain Name System Version >= 13.1.0 <= 17.1.2
F5Big-ip Domain Name System Version17.5.0
F5Big-ip Edge Gateway Version >= 13.1.0 <= 17.1.2
F5Big-ip Edge Gateway Version17.5.0
F5Big-ip Fraud Protection Service Version >= 13.1.0 <= 17.1.2
F5Big-ip Global Traffic Manager Version >= 13.1.0 <= 17.1.2
F5Big-ip Global Traffic Manager Version17.5.0
F5Big-ip Link Controller Version >= 13.1.0 <= 17.1.2
F5Big-ip Link Controller Version17.5.0
F5Big-ip Local Traffic Manager Version >= 13.1.0 <= 17.1.2
F5Big-ip Local Traffic Manager Version17.5.0
F5Big-ip Policy Enforcement Manager Version >= 13.1.0 <= 17.1.2
F5Big-ip Service Proxy Version1.6.0 SwPlatformkubernetes
F5Big-ip Ssl Orchestrator Version >= 13.1.0 <= 17.1.2
F5Big-ip Ssl Orchestrator Version17.5.0
F5Big-ip Webaccelerator Version >= 13.1.0 <= 17.1.2
F5Big-ip Webaccelerator Version17.5.0
F5Big-ip Websafe Version >= 13.1.0 <= 17.1.2
F5Big-ip Websafe Version17.5.0
F5Big-iq Centralized Management Version >= 8.0.0 <= 8.4.0
F5F5os-a Version >= 1.3.0 <= 1.3.2
F5F5os-a Version >= 1.5.0 <= 1.5.3
F5F5os-a Version1.8.0
F5F5os-c Version >= 1.3.0 <= 1.3.2
F5F5os-c Version >= 1.6.0 <= 1.6.2
F5F5os-c Version1.5.0
F5F5os-c Version1.5.1
F5F5os-c Version1.8.0
F5F5os-c Version1.8.1
HpeArubaos-cx Version >= 10.06.0000 < 10.06.0180
   HpeAruba Cx 4100i Version-
   HpeAruba Cx 6100 Version-
   HpeAruba Cx 6200f Version-
   HpeAruba Cx 6200m Version-
   HpeAruba Cx 6300f Version-
   HpeAruba Cx 6300m Version-
   HpeAruba Cx 6405 Version-
   HpeAruba Cx 6410 Version-
   HpeAruba Cx 8320 Version-
   HpeAruba Cx 8325-32c Version-
   HpeAruba Cx 8325-48y8c Version-
   HpeAruba Cx 8360-12c Version-
   HpeAruba Cx 8360-16y2c Version-
   HpeAruba Cx 8360-24xf2c Version-
   HpeAruba Cx 8360-32y4c Version-
   HpeAruba Cx 8360-48xt4c Version-
   HpeAruba Cx 8360-48y6c Version-
   HpeAruba Cx 8400 Version-
HpeArubaos-cx Version >= 10.07.0000 < 10.07.0030
   HpeAruba Cx 4100i Version-
   HpeAruba Cx 6100 Version-
   HpeAruba Cx 6200f Version-
   HpeAruba Cx 6200m Version-
   HpeAruba Cx 6300f Version-
   HpeAruba Cx 6300m Version-
   HpeAruba Cx 6405 Version-
   HpeAruba Cx 6410 Version-
   HpeAruba Cx 8320 Version-
   HpeAruba Cx 8325-32c Version-
   HpeAruba Cx 8325-48y8c Version-
   HpeAruba Cx 8360-12c Version-
   HpeAruba Cx 8360-16y2c Version-
   HpeAruba Cx 8360-24xf2c Version-
   HpeAruba Cx 8360-32y4c Version-
   HpeAruba Cx 8360-48xt4c Version-
   HpeAruba Cx 8360-48y6c Version-
   HpeAruba Cx 8400 Version-
HpeArubaos-cx Version >= 10.08.0000 < 10.08.0010
   HpeAruba Cx 4100i Version-
   HpeAruba Cx 6100 Version-
   HpeAruba Cx 6200f Version-
   HpeAruba Cx 6200m Version-
   HpeAruba Cx 6300f Version-
   HpeAruba Cx 6300m Version-
   HpeAruba Cx 6405 Version-
   HpeAruba Cx 6410 Version-
   HpeAruba Cx 8320 Version-
   HpeAruba Cx 8325-32c Version-
   HpeAruba Cx 8325-48y8c Version-
   HpeAruba Cx 8360-12c Version-
   HpeAruba Cx 8360-16y2c Version-
   HpeAruba Cx 8360-24xf2c Version-
   HpeAruba Cx 8360-32y4c Version-
   HpeAruba Cx 8360-48xt4c Version-
   HpeAruba Cx 8360-48y6c Version-
   HpeAruba Cx 8400 Version-
HpeArubaos-cx Version >= 10.09.0000 < 10.09.0002
   HpeAruba Cx 4100i Version-
   HpeAruba Cx 6100 Version-
   HpeAruba Cx 6200f Version-
   HpeAruba Cx 6200m Version-
   HpeAruba Cx 6300f Version-
   HpeAruba Cx 6300m Version-
   HpeAruba Cx 6405 Version-
   HpeAruba Cx 6410 Version-
   HpeAruba Cx 8320 Version-
   HpeAruba Cx 8325-32c Version-
   HpeAruba Cx 8325-48y8c Version-
   HpeAruba Cx 8360-12c Version-
   HpeAruba Cx 8360-16y2c Version-
   HpeAruba Cx 8360-24xf2c Version-
   HpeAruba Cx 8360-32y4c Version-
   HpeAruba Cx 8360-48xt4c Version-
   HpeAruba Cx 8360-48y6c Version-
   HpeAruba Cx 8400 Version-
StormshieldStormshield Network Security Version >= 2.7.0 < 4.3.16
StormshieldStormshield Network Security Version >= 4.4.0 < 4.6.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 14.68% 0.942
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.