Vulnerability Intelligence Report
CVE-2002-1357
Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.
No Active Exploit Signals
CVSS Base Score
10.0
HIGH
EPSS Probability:9.77%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| cisco | ios | 12.0s, 12.0st, 12.1e, 12.1ea, 12.1t, 12.2, 12.2s, 12.2t |
| fissh | ssh_client | 1.0a_for_windows |
| intersoft | securenetterm | 5.4.1 |
| netcomposite | shellguard_ssh | 3.4.6 |
| pragma_systems | secureshell | 2.0 |
| putty | putty | 0.48, 0.49, 0.53 |
| winscp | winscp | 2.0.0 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
9.767%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | MITRE Corporation · N/A · USA |
| Reserved | 2002-12-14T00:00:00 |
| Published | 2002-12-17T05:00:00 |
| Patch Date | 2002-12-16 |
| Last Updated | 2024-08-08T03:19:28 |
Community Chatter & Buzz