Security advisories, knowledge base and other articles about D(HE)at attack and related issues.
TraceSecurity
What is the DHEAT Vulnerability?
Sindastra
How to harden OpenSSH server
Amazon Linux Security Center
ALAS-2024-727
News.de
IT-Sicherheit: UNIX und Windows bedroht - Update für IT-Sicherheitshinweis zu Diffie-Hellman Implementierungen (Risiko: mittel)
SUSE Update Advisories
Security update for openssl-3
Szilárd Pfeiffer
How Diffie-Hellman Key Exchange can Cause Availability Issues
Google Cloud
Release 1.30.0-gke.1930
Red Hat Customer Portal
CVE-2024-41996
SUSE CVE Database
CVE-2024-41996
Security | Ubuntu
CVE-2024-41996
Cyber Security News
D(HE)at Attack – 20-Yr-old Flaw Let Attackers Exploit Diffie-Hellman Protocol To Over-Heat Your CPU
Ubuntu
USN-6854-1: OpenSSL vulnerability
Positron Security
An Analysis of the DHEat DoS Against SSH in Cloud Environments
ssh-audit
v3.2.0 Release
--dheat option; CVE-2002-20001).
CryptoLyzer
0.12.2 Changelog
IEEE Access
D(HE)at: A Practical Denial-of-Service Attack on the Finite Field Diffie–Hellman Key Exchange
Extreme Networks
SA-2023-059 - DHEat attack (CVE-2002-20001)
The Diffie-Hellman Key Agreement Protocol enables remote attackers to send arbitrary numbers without public keys, triggering costly server-side DHE modular-exponentiation calculations. This attack requires minimal CPU resources and bandwidth, and may be more disruptive in cases where clients require server selection of largest supported key size.
Ciphersuite Info
Diffie-Hellman Ephemeral Key Exchange DoS Vulnerability (SSL/TLS, D(HE)ater)
The so-called DHEat Attack affects cryptographic protocols using the Diffie Hellman key exchange (incl. TLS). According to its authors, it exploits a potocol particularity that may allow attackers to perform a DoS attack “with a low-bandwidth network connection without authentication, privilege, or user interaction.”
CryptoLyzer
0.8.4 Changelog
WolfSSL
DHE Vulnerability of CVE 2022-40735
Customers have asked about CVE 2022-40735 and whether they are vulnerable as users of wolfSSL. The short is answer is: No. But, there are ways that you can put yourself at risk. Let’s delve into the CVE and how best to protect yourself from attacks like this.
Ubuntu
CVE-2022-40735
NIST
NVD - CVE-2022-40735
Siemens
SSA-506569: Multiple Vulnerabilities in SCALANCE W1750D
The SCALANCE W1750D device contains multiple vulnerabilities that could allow an attacker to inject commands or exploit buffer overflow vulnerabilities which could lead to denial of service, unauthenticated remote code execution or stored XSS.
Siemens has released updates for the affected products and recommends to update to the latest versions.
OpenSSL
Configuring Supported TLS Groups in OpenSSL
The configuration of supported groups in TLS servers is important to limit the resource consumption of the TLS handshakes performed by the server. This blog post should give system administrators a few useful hints on how to configure the OpenSSL library and two of the most used open source HTTP servers which use the OpenSSL library for supporting the HTTPS protocol.
The CVE-2002-20001 (a.k.a DHEat attack) vulnerability inherent to the support of the Diffie-Hellman (DH) and Elliptic Curve Diffie-Hellman (ECDH) key exchanges in TLS and other protocols provides a way for an attacker to cause high CPU usage on servers with relatively low effort on the client side.
Microfocus
Diffie-Hellman Key Agreement Protocol vulnerability for Reflection for Secure IT for UNIX
Mitigation for the vulnerability referenced in CVE-2002-20001
F5 Networks
K83120834: Diffie-Hellman key agreement protocol weaknesses CVE-2002-20001 & CVE-2022-40735
SUSE
Security Vulnerability: DHEater aka CVE-2002-20001
Security researchers from Balasys have published a new attack on Diffie-Hellman key exchange which allows remote attackers to attack network facing SSL / TLS / HTTPS / SSH services leading to excessive compute time usage even by sending small amounts of network traffic even before authentication.
All applications on SUSE Linux Enterprise are affected that have DHE enabled. The Diffie-Hellman Epheremal key exchange is usually configured by default to provide perfect forward secrecy.
Aruba
AOS-CX Switches Multiple Vulnerabilities
Aruba has released updates for wired switch products running AOS-CX that address multiple security vulnerabilities.
NIST
NVD - CVE-2002-20001
The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network bandwidth. The attack may be more disruptive in cases where a client can require a server to select its largest supported key size. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE.