CVE-2002-20001
published 2021-11-11CVE-2002-20001: The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and…
PriorityP358high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
23.06%
97.5th percentile
The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network bandwidth. The attack may be more disruptive in cases where a client can require a server to select its largest supported key size. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE.
Affected
64 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip_access_policy_manager | >= 13.1.0 < 16.1.4 | 16.1.4 |
| f5 | big-ip_access_policy_manager | >= 17.0.0 < 17.1.0 | 17.1.0 |
| f5 | big-ip_advanced_firewall_manager | — | — |
| f5 | big-ip_advanced_firewall_manager | 13.1.0 – 17.1.2 | — |
| f5 | big-ip_advanced_web_application_firewall | — | — |
| f5 | big-ip_advanced_web_application_firewall | 13.1.0 – 17.1.2 | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | 13.1.0 – 17.1.2 | — |
| f5 | big-ip_application_acceleration_manager | — | — |
| f5 | big-ip_application_acceleration_manager | 13.1.0 – 17.1.2 | — |
| f5 | big-ip_application_security_manager | — | — |
| f5 | big-ip_application_security_manager | 13.1.0 – 17.1.2 | — |
| f5 | big-ip_application_visibility_and_reporting | — | — |
| f5 | big-ip_application_visibility_and_reporting | 13.1.0 – 17.1.2 | — |
| f5 | big-ip_carrier-grade_nat | — | — |
| f5 | big-ip_carrier-grade_nat | 13.1.0 – 17.1.2 | — |
| f5 | big-ip_ddos_hybrid_defender | — | — |
| f5 | big-ip_ddos_hybrid_defender | 13.1.0 – 17.1.2 | — |
| f5 | big-ip_domain_name_system | — | — |
| f5 | big-ip_domain_name_system | 13.1.0 – 17.1.2 | — |
| f5 | big-ip_edge_gateway | — | — |
| f5 | big-ip_edge_gateway | 13.1.0 – 17.1.2 | — |
| f5 | big-ip_fraud_protection_service | — | — |
| f5 | big-ip_fraud_protection_service | 13.1.0 – 17.1.2 | — |
| f5 | big-ip_global_traffic_manager | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SCALANCE W1750D
cisa_ics·2022-11-10
Siemens SCALANCE W1750D
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SCALANCE W1750D
Last RevisedNovember 10, 2022
Alert CodeICSA-22-314-10
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE W1750D
- Vulnerabilities: Uncontrolled Resource Consumption, Buffer Copy without Checking Size of Input, Improper Neutralization of Input During Web Page Generation, Improper Neutralization of Special Elements used in a Command, Improper Input Validation
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to inject comman
OSV
CVE-2022-40735: The Diffie-Hellman Key Agreement Protocol allows use of long exponents that arguably make certain calculations unnecessarily expensive, because the 19
osv·2022-11-14·CVSS 7.5
CVE-2022-40735 [HIGH] CVE-2022-40735: The Diffie-Hellman Key Agreement Protocol allows use of long exponents that arguably make certain calculations unnecessarily expensive, because the 19
The Diffie-Hellman Key Agreement Protocol allows use of long exponents that arguably make certain calculations unnecessarily expensive, because the 1996 van Oorschot and Wiener paper found that "(appropriately) short exponents" can be used when there are adequate subgroup constraints, and these short exponents can lead to less expensive calculations than for long exponents. This issue is different from CVE-2002-20001 because it is based on an observation about exponent size, rather than an observation about numbers that are not public keys. The specific situations in which calculation expense would constitute a server-side vulnerability depend on the protocol (e.g., TLS, SSH, or IKE) and the DHE implementation details. In general, there might be an availability concern because of server-si
GHSA
GHSA-jx4r-qc68-xjr5: The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys,
ghsa_unreviewed·2022-04-21
CVE-2002-20001 [HIGH] CWE-400 GHSA-jx4r-qc68-xjr5: The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys,
The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)ater attack. The client needs very little CPU resources and network bandwidth. The attack may be more disruptive in cases where a client can require a server to select its largest supported key size. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
OWASP
Transport Layer Security Cheat Sheet
owasp
Transport Layer Security Cheat Sheet
# Transport Layer Security Cheat Sheet
## Introduction
This cheat sheet provides guidance on implementing transport layer protection for applications using Transport Layer Security (TLS). It primarily focuses on how to use TLS to protect clients connecting to a web application over HTTPS, though much of this guidance is also applicable to other uses of TLS. When correctly implemented, TLS can provide several security benefits:
- **Confidentiality**: Provides protection against attackers reading the contents of the traffic.
- **Integrity**: Provides protection against traffic modification, such as an attacker replaying requests against the server.
- **[Authentication](Authentication_Cheat_Sheet.md)**: Enables the client to confirm they are connected to the legitimate server. Note that th
CWE
Asymmetric Resource Consumption (Amplification)
mitre_cwe
CWE-405 Asymmetric Resource Consumption (Amplification)
CWE-405: Asymmetric Resource Consumption (Amplification)
The product does not properly control situations in which an adversary can cause the product to consume or produce excessive resources without requiring the adversary to invest equivalent work or otherwise prove authorization, i.e., the adversary's influence is "asymmetric."
This can lead to poor performance due to "amplification" of resource consumption, typically in a non-linear fashion. This situation is worsened if the product allows malicious users or attackers to consume more resources than their access level permits.
Modes of Introduction:
Phase: Architecture and Design
Phase: Implementation
Phase: Operation
Common Consequences:
Scope: Availability. Impact: DoS: Amplification, DoS: Resource Consumption (CPU), DoS: Resource
https://cert-portal.siemens.com/productcert/pdf/ssa-506569.pdfhttps://dheatattack.comhttps://dheatattack.gitlab.io/https://github.com/Balasys/dheaterhttps://github.com/mozilla/ssl-config-generator/issues/162https://gitlab.com/dheatattack/dheaterhttps://ieeexplore.ieee.org/document/10374117https://support.f5.com/csp/article/K83120834https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-004.txthttps://www.openssl.org/blog/blog/2022/10/21/tls-groups-configuration/https://www.reddit.com/r/netsec/comments/qdoosy/server_overload_by_enforcing_dhe_key_exchange/https://www.researchgate.net/profile/Anton-Stiglic-2/publication/2401745_Security_Issues_in_the_Diffie-Hellman_Key_Agreement_Protocolhttps://www.suse.com/support/kb/doc/?id=000020510https://cert-portal.siemens.com/productcert/pdf/ssa-506569.pdfhttps://dheatattack.comhttps://dheatattack.gitlab.io/https://github.com/Balasys/dheaterhttps://github.com/mozilla/ssl-config-generator/issues/162https://gitlab.com/dheatattack/dheaterhttps://ieeexplore.ieee.org/document/10374117https://support.f5.com/csp/article/K83120834https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-004.txthttps://www.openssl.org/blog/blog/2022/10/21/tls-groups-configuration/https://www.reddit.com/r/netsec/comments/qdoosy/server_overload_by_enforcing_dhe_key_exchange/https://www.researchgate.net/profile/Anton-Stiglic-2/publication/2401745_Security_Issues_in_the_Diffie-Hellman_Key_Agreement_Protocolhttps://www.suse.com/support/kb/doc/?id=000020510
2021-11-11
Published