Resource exhaustion in Aruba Instant and ArubaOS (AOS) - CVE-2002-20001
Published: September 30, 2022 / Updated: May 4, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources in the Diffie-Hellman Key Agreement Protocol. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
ArubaOS (AOS)
ClearPass Policy Manager
IBM Automation Decision Services
How to mitigate CVE-2002-20001
ArubaOS (AOS) - update to 10.3.1.1
ClearPass Policy Manager - addressed in versions 6.9.13, 6.10.8, 6.11.0
IBM Automation Decision Services - update to 24.0.0.0.4
Links to Public Exploits and PoC-codes
- Exploit #9033 - dheater (D(HE)ater is a proof of concept implementation of the D(HE)at attack (CVE-2002-20001) through which denial-of-service can be performed by enforcing the Diffie-Hellman key exchange. (read-only clone of the original GitLab project)) (May 4, 2023)
- Exploit #8425 - dheater (D(HE)ater is a proof of concept implementation of the D(HE)at attack (CVE-2002-20001) through which denial-of-service can be performed by enforcing the Diffie-Hellman key exchange.) (October 2, 2022)