← Vulnerability feed

Vulnerability record · CVE-2002-0656 · published 12 August 2002

CVE-2002-0656: OpenSSL SSL2/SSL3 buffer overflows allow remote code execution

OOpenssl · Openssl

OpenSSL 0.9.6d and earlier and 0.9.7-beta2 and earlier contain buffer overflows reachable through SSL2 client master key and SSL3 session ID handling. A remote attacker can trigger the overflow and potentially execute arbitrary code in the context of the affected service. The flaw affects a widely deployed cryptographic library and its downstream products.

7.5 CVSS 2.0 High EPSS 90% · top 0.2%
7.5CVSS 2.0 base score
90%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
24References
16 Jun 2026Last modified by NVD

Description

Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a large client master key in SSL2 or (2) a large session ID in SSL3.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityRemote, unauthenticated code execution in a core cryptographic library with very high EPSS, though no KEV listing or documented exploit tags in the record.

What it is

OpenSSL 0.9.6d and earlier and 0.9.7-beta2 and earlier contain buffer overflows reachable through SSL2 client master key and SSL3 session ID handling. A remote attacker can trigger the overflow and potentially execute arbitrary code in the context of the affected service. The flaw affects a widely deployed cryptographic library and its downstream products.

Impact

An attacker gains the ability to execute arbitrary code on the vulnerable host, or at minimum crash the SSL service, depending on the overflow's controllability. This can lead to full compromise of the process handling TLS/SSL connections.

Attack surface

The flaw is network-reachable (AV:N) with no authentication required (Au:N) and low attack complexity (AC:L), triggered by malformed SSL2 or SSL3 handshake data sent to a listening service. No user interaction is indicated by the vector or description.

Exploitation

Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is very high (0.8982, 99.78th percentile), indicating substantial predicted exploitation activity. Reference tags are limited to US Government Resource advisories with no explicit exploit or weaponization tags.

What to do

  • Upgrade OpenSSL to a version later than 0.9.6d / 0.9.7-beta2, or apply the vendor patch for your distribution.
  • Disable SSL2 and SSL3 where possible and require TLS 1.0 or later to remove the vulnerable handshake paths.
  • Update downstream products listed (Oracle Application Server, HTTP Server, Apple Mac OS X, Corporate Time Outlook Connector) to their patched releases.
  • Restrict network exposure of SSL/TLS services to trusted clients until patching is complete.

Detection

  • Monitor for crashes or abnormal termination of SSL/TLS services that could indicate malformed handshake attempts.
  • Inspect network traffic for oversized SSL2 client master key or SSL3 session ID fields in handshake records.
  • Correlate IDS/IPS alerts for OpenSSL handshake anomalies with host logs on systems running unpatched OpenSSL.
  • Audit installed OpenSSL versions across hosts to identify systems still on 0.9.6d/0.9.7-beta2 or earlier.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2002-0656 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-21962Oracle HTTP Server and WebLogic Proxy Plug-in improper access controlOracle HTTP Server and the WebLogic Server Proxy Plug-in (for Apache HTTP Server and IIS) contain an improper access control flaw (CWE-284) in suppor…KEVEPSS 71%analysed9.8CVE-2021-1870Apple WebKit logic flaw allows remote code executionA logic issue in Apple's WebKit was addressed with improved restrictions, affecting macOS Big Sur, Catalina, Mojave, iOS and iPadOS, plus WebKitGTK a…KEVEPSS 7.7%analysed9.8CVE-2021-1871Apple WebKit logic flaw allows remote code executionA logic issue in Apple's WebKit was addressed with improved restrictions. It affects macOS Big Sur, Catalina, Mojave, iOS and iPadOS, and a remote at…KEVEPSS 7.0%analysed9.8CVE-2014-7169GNU Bash environment variable function parsing command injection (Shellshock variant)GNU Bash through 4.3 bash43-025 processes trailing strings after malformed function definitions in environment variable values, allowing command inje…KEVEPSS 100%analysed9.8CVE-2014-6271GNU Bash environment variable command injection (ShellShock)GNU Bash through 4.3 processes trailing strings after function definitions in environment variable values, allowing injected commands to run when Bas…KEVEPSS 100%analysed9.8CVE-2012-1823PHP-CGI query string option injection enables remote code executionPHP versions before 5.3.12 and 5.4.x before 5.4.2, when run as a CGI script (php-cgi), mishandle query strings that lack an equals sign, allowing com…KEVEPSS 100%analysed9.0CVE-2021-40438Apache HTTP Server mod_proxy SSRF via crafted URI pathA crafted request URI path can make mod_proxy forward the request to an origin server chosen by the remote user, an SSRF flaw in Apache HTTP Server 2…KEVEPSS 100%analysed8.8CVE-2022-2294Google Chrome WebRTC heap buffer overflow via crafted HTML pageCVE-2022-2294 is a heap buffer overflow in the WebRTC component of Google Chrome prior to 103.0.5060.114. A remote attacker can trigger heap corrupti…KEVEPSS 70%analysed

Source: NIST National Vulnerability Database (record CVE-2002-0656), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.