CVE-2002-1359
Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code via buffer overflow attacks, as demonstrated by the SSHredder SSH…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 80.2%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code via buffer overflow attacks, as demonstrated by the SSHredder SSH protocol test suite.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 80.23% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- cisco/ios · fissh/ssh client · intersoft/securenetterm · netcomposite/shellguard ssh · pragma systems/secureshell · putty/putty · winscp/winscp
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0110.htmlVendor Advisory
- http://securitytracker.com/id?1005812
- http://securitytracker.com/id?1005813
- http://www.cert.org/advisories/CA-2002-36.htmlThird Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/6407
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10870
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5848
- http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0110.htmlVendor Advisory
- http://securitytracker.com/id?1005812
- http://securitytracker.com/id?1005813
- http://www.cert.org/advisories/CA-2002-36.htmlThird Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/6407
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10870
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5848
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.