SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2002-1359

Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code via buffer overflow attacks, as demonstrated by the SSHredder SSH…

HIGH 10.0EPSS 80.2%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 80.2%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.

Description

Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code via buffer overflow attacks, as demonstrated by the SSHredder SSH protocol test suite.

CVSS 2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
80.23% probability · 100th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
cisco/ios · fissh/ssh client · intersoft/securenetterm · netcomposite/shellguard ssh · pragma systems/secureshell · putty/putty · winscp/winscp
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.