← Vulnerability feed

Vulnerability record · CVE-2002-1059 · published 4 October 2002

CVE-2002-1059: SecureCRT SSH client buffer overflow via SSH1 version string

Van Dyke Technologies · Securecrt

Van Dyke SecureCRT SSH client versions before 3.4.6 and 4.x before 4.0 beta 3 contain a buffer overflow when handling a long SSH1 protocol version string. Because the string comes from the remote SSH server, a malicious or compromised server can overflow the client during connection setup. The flaw matters because the client is the trusted endpoint in an SSH session, so the usual trust direction is reversed.

7.5 CVSS 2.0 High EPSS 60% · top 0.9%
7.5CVSS 2.0 base score
60%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Buffer overflow in Van Dyke SecureCRT SSH client before 3.4.6, and 4.x before 4.0 beta 3, allows an SSH server to execute arbitrary code via a long SSH1 protocol version string.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityRemote code execution on the client with no authentication required and public exploit material, though the product is old and the record lacks modern scoring detail.

What it is

Van Dyke SecureCRT SSH client versions before 3.4.6 and 4.x before 4.0 beta 3 contain a buffer overflow when handling a long SSH1 protocol version string. Because the string comes from the remote SSH server, a malicious or compromised server can overflow the client during connection setup. The flaw matters because the client is the trusted endpoint in an SSH session, so the usual trust direction is reversed.

Impact

An attacker controlling the SSH server can execute arbitrary code on the connecting client, giving them the user's privileges and access to credentials and data handled by that session.

Attack surface

Reached over the network when the client connects to an SSH server that returns an oversized SSH1 protocol version string; no authentication or user interaction beyond initiating the connection is required, per the AV:N/AC:L/Au:N vector.

Exploitation

Not listed in CISA KEV, but EPSS is high (0.603, ~99th percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit material exists.

What to do

  • Upgrade SecureCRT to 3.4.6 or later, or to 4.0 beta 3 or later, per the vendor advisory.
  • Where upgrades are not possible, restrict SSH connections to trusted servers and avoid SSH1 where feasible.
  • Treat connecting to untrusted or third-party SSH servers as a code-execution risk on unpatched clients.
  • Inventory endpoints still running SecureCRT 3.x or early 4.x builds and prioritize them for remediation.

Detection

  • Monitor for SecureCRT client crashes or abnormal process termination during SSH connection establishment.
  • Hunt for unexpected child processes or network connections spawned by the SecureCRT process.
  • Review SSH server logs for oversized or malformed SSH1 protocol version banners.
  • Track endpoint software inventory for SecureCRT versions below 3.4.6 or 4.0 beta 3.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2002-1059 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2002-1059), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.