CVE Feed

    Dashboard / CVE / CVE-2002-20001

    CVE-2002-20001

    The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network bandwidth. The attack may be more disruptive in cases where a client can require a server to select its largest supported key size. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE.

    Published:Nov 11, 2021
    Last Modified:Aug 22, 2025
    EPS:Nov 11, 2021
    EPSS Score:0.1468
    CVSS Score:7.5

    Affected Products

    Vendor
    Balasys
    Product
    Dheater
    Vendor
    F5
    Product
    Big-ip Access Policy Manager
    Vendor
    F5
    Product
    Big-ip Advanced Firewall Manager
    Vendor
    F5
    Product
    Big-ip Advanced Web Application Firewall
    Vendor
    F5
    Product
    Big-ip Analytics
    Vendor
    F5
    Product
    Big-ip Application Acceleration Manager
    Vendor
    F5
    Product
    Big-ip Application Security Manager
    Vendor
    F5
    Product
    Big-ip Application Visibility And Reporting
    Vendor
    F5
    Product
    Big-ip Carrier-grade Nat
    Vendor
    F5
    Product
    Big-ip Ddos Hybrid Defender
    Vendor
    F5
    Product
    Big-ip Domain Name System
    Vendor
    F5
    Product
    Big-ip Edge Gateway
    Vendor
    F5
    Product
    Big-ip Fraud Protection Service
    Vendor
    F5
    Product
    Big-ip Global Traffic Manager
    Vendor
    F5
    Product
    Big-ip Link Controller
    Vendor
    F5
    Product
    Big-ip Local Traffic Manager
    Vendor
    F5
    Product
    Big-ip Policy Enforcement Manager
    Vendor
    F5
    Product
    Big-ip Service Proxy
    Vendor
    F5
    Product
    Big-ip Ssl Orchestrator
    Vendor
    F5
    Product
    Big-ip Webaccelerator
    Vendor
    F5
    Product
    Big-ip Websafe
    Vendor
    F5
    Product
    Big-iq Centralized Management
    Vendor
    F5
    Product
    F5os-a
    Vendor
    F5
    Product
    F5os-c
    Vendor
    F5
    Product
    Traffix Signaling Delivery Controller
    Vendor
    Hpe
    Product
    Aruba Cx 4100i
    Vendor
    Hpe
    Product
    Aruba Cx 6100
    Vendor
    Hpe
    Product
    Aruba Cx 6200f
    Vendor
    Hpe
    Product
    Aruba Cx 6200m
    Vendor
    Hpe
    Product
    Aruba Cx 6300f
    Vendor
    Hpe
    Product
    Aruba Cx 6300m
    Vendor
    Hpe
    Product
    Aruba Cx 6405
    Vendor
    Hpe
    Product
    Aruba Cx 6410
    Vendor
    Hpe
    Product
    Aruba Cx 8320
    Vendor
    Hpe
    Product
    Aruba Cx 8325-32c
    Vendor
    Hpe
    Product
    Aruba Cx 8325-48y8c
    Vendor
    Hpe
    Product
    Aruba Cx 8360-12c
    Vendor
    Hpe
    Product
    Aruba Cx 8360-16y2c
    Vendor
    Hpe
    Product
    Aruba Cx 8360-24xf2c
    Vendor
    Hpe
    Product
    Aruba Cx 8360-32y4c
    Vendor
    Hpe
    Product
    Aruba Cx 8360-48xt4c
    Vendor
    Hpe
    Product
    Aruba Cx 8360-48y6c
    Vendor
    Hpe
    Product
    Aruba Cx 8400
    Vendor
    Hpe
    Product
    Arubaos-cx
    Vendor
    Siemens
    Product
    Scalance W1750d
    Vendor
    Siemens
    Product
    Scalance W1750d Firmware
    Vendor
    Stormshield
    Product
    Stormshield Management Center
    Vendor
    Stormshield
    Product
    Stormshield Network Security
    Vendor
    Suse
    Product
    Linux Enterprise Server

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High