The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network bandwidth. The attack may be more disruptive in cases where a client can require a server to select its largest supported key size. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Aruba Aos 10 | — | In order to address the vulnerabilities described above for the affected release branches, it is recommended to upgrade the software to the following versions:
- Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.21 and above
- Aruba InstantOS 6.5.x: 6.5.4.24 and above
- Aruba InstantOS 8.6.x: 8.6.0.19 and above
- Aruba InstantOS 8.7.x: 8.7.1.10 and above
- Aruba InstantOS 8.10.x: 8.10.0.2 and above
- ArubaOS 10.3.x: 10.3.1.1 and above
Aruba does not evaluate or patch Aruba InstantOS and ArubaOS 10 software branches that have reached their End of Support (EoS) milestone. For more information about Aruba's End of Support policy visit:
https://www.arubanetworks.com/support-services/end-of-life/ | Jan 14, 2025 | Sep 27, 2022 |
| Aruba Aos Cx | — | The vulnerabilities contained in this advisory can be addressed
by patching or upgrading to one of the versions listed below
AOS-CX 10.06.xxxx: 10.06.0180 and above
AOS-CX 10.07.xxxx: 10.07.0061 and above
AOS-CX 10.08.xxxx: 10.08.1040 and above
AOS-CX 10.09.xxxx: 10.09.0010 and above
Aruba recommends that users using the following branches
upgrade to 10.06.0180 and above to address these vulnerabilities:
AOS-CX 10.05.xxxx and below
None of the above branch versions will address the UEFI
vulnerabilities mentioned in ARUBA-PSA-2022-001. | Feb 24, 2025 | Feb 22, 2022 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | May 19, 2022 |
| Suse | — | Upgrade libopenssl1_1-hmac-32bitUpgrade libopenssl1_1-32bitUpgrade libopenssl-1_1-develUpgrade libopenssl1_1-hmacUpgrade libopenssl1_1Upgrade openssl-1_1 | Aug 9, 2024 | Nov 11, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub