Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2002-20001

EPSS 14.68% · P95
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2002-20001

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network bandwidth. The attack may be more disruptive in cases where a client can require a server to select its largest supported key size. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Diffie-Hellman Key Agreement Protocol 资源管理错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Diffie-Hellman Key Agreement Protocol是一种密钥协商协议。它最初在 Diffie 和 Hellman 关于公钥密码学的开创性论文中有所描述。该密钥协商协议允许 Alice 和 Bob 交换公钥值,并根据这些值和他们自己对应的私钥的知识,安全地计算共享密钥K,从而实现进一步的安全通信。仅知道交换的公钥值,窃听者无法计算共享密钥。 Diffie-Hellman Key Agreement Protocol 存在资源管理错误漏洞,远程攻击者可以发送实际上不是公钥的任意数字,并
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2002-20001

#POC DescriptionSource LinkShenlong Link
1D(HE)ater is a proof of concept implementation of the D(HE)at attack (CVE-2002-20001) through which denial-of-service can be performed by enforcing the Diffie-Hellman key exchange. (read-only clone of the original GitLab project)https://github.com/c0r0n3r/dheaterPOC Details
2POC for Testing the Existence of D(HE)at DOS Attack for (CVE-2002-20001)https://github.com/itmaniac/dheat_dos_attack_pocPOC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2002-20001

Please Login to view more intelligence information

Same Patch Batch · n/a · 2021-11-11 · 8 CVEs total

CVE-2021-43397LiquidFiles 安全漏洞
CVE-2021-42002Zoho Corporation ADManager Plus 安全漏洞
CVE-2021-41833Zoho ManageEngine Patch Connect Plus 代码问题漏洞
CVE-2021-41081Zoho Corporation Zoho ManageEngine Network Configuration Manager SQL注入漏洞
CVE-2021-41080Zoho Corporation Zoho ManageEngine Network Configuration Manager SQL注入漏洞
CVE-2021-43573Realtek RTL8195AM 缓冲区错误漏洞
CVE-2021-42847Zoho Corporation Zoho ManageEngine Adaudit Plus 其他漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2002-20001

No comments yet


Leave a comment