Description
The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network bandwidth. The attack may be more disruptive in cases where a client can require a server to select its largest supported key size. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE.
Exploits (2)
References (13)
Core 13
Core References
Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-506569.pdf
Third Party Advisory
https://dheatattack.com
Third Party Advisory
https://dheatattack.gitlab.io/
Product, Third Party Advisory
https://github.com/Balasys/dheater
Issue Tracking
https://github.com/mozilla/ssl-config-generator/issues/162
Third Party Advisory
https://gitlab.com/dheatattack/dheater
Technical Description, Third Party Advisory
https://ieeexplore.ieee.org/document/10374117
Third Party Advisory
https://support.f5.com/csp/article/K83120834
Technical Description, Third Party Advisory
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-004.txt
Third Party Advisory
https://www.openssl.org/blog/blog/2022/10/21/tls-groups-configuration/
Issue Tracking
https://www.reddit.com/r/netsec/comments/qdoosy/server_overload_by_enforcing_dhe_key_exchange/
Exploit, Technical Description
https://www.researchgate.net/profile/Anton-Stiglic-2/publication/2401745_Security_Issues_in_the_Diffie-Hellman_Key_Agreement_Protocol
Third Party Advisory
https://www.suse.com/support/kb/doc/?id=000020510
Scores
CVSS v3
7.5
EPSS
0.1468
EPSS Percentile
94.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-400
Status
published
Products (50)
balasys/dheater
f5/big-ip_access_policy_manager
13.1.0 - 16.1.4
f5/big-ip_advanced_firewall_manager
17.5.0
f5/big-ip_advanced_firewall_manager
13.1.0 - 17.1.2
f5/big-ip_advanced_web_application_firewall
17.5.0
f5/big-ip_advanced_web_application_firewall
13.1.0 - 17.1.2
f5/big-ip_analytics
17.5.0
f5/big-ip_analytics
13.1.0 - 17.1.2
f5/big-ip_application_acceleration_manager
17.5.0
f5/big-ip_application_acceleration_manager
13.1.0 - 17.1.2
... and 40 more
Published
Nov 11, 2021
Tracked Since
Feb 18, 2026