CVE-2002-1358
Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.84%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 5.84% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- cisco/ios · fissh/ssh client · intersoft/securenetterm · netcomposite/shellguard ssh · pragma systems/secureshell · putty/putty · winscp/winscp
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0110.html
- http://securitytracker.com/id?1005812
- http://securitytracker.com/id?1005813
- http://www.cert.org/advisories/CA-2002-36.htmlThird Party Advisory, US Government Resource
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5721
- http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0110.html
- http://securitytracker.com/id?1005812
- http://securitytracker.com/id?1005813
- http://www.cert.org/advisories/CA-2002-36.htmlThird Party Advisory, US Government Resource
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5721
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.