PT-2021-8284 · Unknown · Diffie-Hellman Key Agreement Protocol

Published

2021-11-11

·

Updated

2025-08-22

·

CVE-2002-20001

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Diffie-Hellman Key Agreement Protocol (affected versions not specified)
Description The Diffie-Hellman Key Agreement Protocol allows remote attackers to send arbitrary numbers that are not public keys, triggering expensive server-side DHE modular-exponentiation calculations, also known as a D(HE)at or D(HE)ater attack. This attack can be more disruptive when a client requires a server to select its largest supported key size. The client needs minimal CPU resources and network bandwidth to perform the attack. The basic attack scenario involves the client claiming it can only communicate with DHE, and the server must be configured to allow DHE.
Recommendations As a temporary workaround, consider disabling the Diffie-Hellman (DHE) key exchange until a patch is available. Restrict access to DHE key exchange to minimize the risk of exploitation. Avoid using DHE key exchange in cases where a client can require a server to select its largest supported key size until the issue is resolved.

Exploit

Fix

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BDU:2025-06599
CVE-2002-20001
OPENSUSE-SU-2024:11905-1
OPENSUSE-SU-2024:13932-1

Affected Products

Diffie-Hellman Key Agreement Protocol