CVE-2002-20001: High severity balasys dheater vulnerability
The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network bandwidth. The attack may be more disruptive in cases where a client can require a server to select its largest supported key size. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE.
Other sources
The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)ater attack. The client needs very little CPU resources and network bandwidth. The attack may be more disruptive in cases where a client can require a server to select its largest supported key size. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2002-20001?
CVE-2002-20001 has a moderate severity, as it allows remote attackers to perform resource-intensive calculations on the server.
How do I fix CVE-2002-20001?
To fix CVE-2002-20001, upgrade affected software versions to their patched releases, such as F5 BIG-IP to versions 17.1.0 or 16.1.4.
Which products are affected by CVE-2002-20001?
Affected products include F5 BIG-IP (APM), F5 BIG-IQ Centralized Management, and various versions of F5 OS products.
What type of attack does CVE-2002-20001 enable?
CVE-2002-20001 enables a D(HE)at or D(HE)ater attack, where attackers can exploit the Diffie-Hellman protocol to cause server-side resource strain.
How can I detect if my system is vulnerable to CVE-2002-20001?
To detect vulnerability to CVE-2002-20001, check if any affected F5 products are running vulnerable versions as specified in the vulnerability report.