#VU98050 Resource exhaustion in Diffie-Hellman key exchange - CVE-2024-41996
Published: October 6, 2024
Diffie-Hellman key exchange
Diffie-Hellman key exchange
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to unnecessary validation of the public keys in the Diffie-Hellman Key Agreement Protocol when an approved safe prime is used. A remote attacker from the client side can trigger unnecessarily expensive server-side DHE modular-exponentiation calculations and cause asymmetric resource consumption, resulting in a denial of service (DoS) attack.