High severity7.5NVD Advisory· Published Nov 11, 2021· Updated Jun 16, 2026
CVE-2002-20001
CVE-2002-20001
Description
The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network bandwidth. The attack may be more disruptive in cases where a client can require a server to select its largest supported key size. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
11- cpe:2.3:a:stormshield:stormshield_management_center:*:*:*:*:*:*:*:*Range: <3.3.3
- cpe:2.3:a:stormshield:stormshield_network_security:*:*:*:*:*:*:*:*Range: >=2.7.0,<4.3.16
- cpe:2.3:o:siemens:scalance_w1750d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:11:-:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:suse:linux_enterprise_server:11:-:*:*:*:*:*:*
- cpe:2.3:o:suse:linux_enterprise_server:12:-:*:*:*:*:*:*
- cpe:2.3:o:suse:linux_enterprise_server:15:*:*:*:*:*:*:*
- Diffie-Hellman Key Agreement Protocol/Diffie-Hellman Key Agreement Protocoldescription
- osv-coords2 versionspkg:rpm/opensuse/openssl-1_1&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/ssh-audit&distro=openSUSE%20Tumbleweed
< 1.1.1m-4.1+ 1 more
- (no CPE)range: < 1.1.1m-4.1
- (no CPE)range: < 3.2.0-1.1
Patches
Vulnerability mechanics
References
11- www.researchgate.net/profile/Anton-Stiglic-2/publication/2401745_Security_Issues_in_the_Diffie-Hellman_Key_Agreement_ProtocolnvdExploitTechnical Description
- cert-portal.siemens.com/productcert/pdf/ssa-506569.pdfnvdThird Party Advisory
- dheatattack.comnvdThird Party Advisory
- dheatattack.gitlab.ionvdThird Party Advisory
- ieeexplore.ieee.org/document/10374117nvdTechnical DescriptionThird Party Advisory
- support.f5.com/csp/article/K83120834nvdThird Party Advisory
- www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-004.txtnvdTechnical DescriptionThird Party Advisory
- www.openssl.org/blog/blog/2022/10/21/tls-groups-configuration/nvdThird Party Advisory
- www.suse.com/support/kb/doc/nvdThird Party Advisory
- github.com/mozilla/ssl-config-generator/issues/162nvdIssue Tracking
- www.reddit.com/r/netsec/comments/qdoosy/server_overload_by_enforcing_dhe_key_exchange/nvdIssue Tracking
News mentions
0No linked articles in our index yet.