Vulnerability record · CVE-2002-1120 · published 24 September 2002
CVE-2002-1120: Savant Web Server buffer overflow via long HTTP GET request
Savant · Savant Web Server
Savant Web Server 3.1 and earlier contains a buffer overflow that is triggered by a long HTTP GET request. A remote, unauthenticated attacker can send an oversized request to corrupt memory and potentially execute arbitrary code on the server. The flaw is in an old, likely unsupported web server, so exposure depends on whether the product is still deployed.
Description
Buffer overflow in Savant Web Server 3.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityThe flaw is remotely exploitable without authentication, has a high EPSS score and public exploit code, though it affects an old web server that may have limited deployment.
What it is
Savant Web Server 3.1 and earlier contains a buffer overflow that is triggered by a long HTTP GET request. A remote, unauthenticated attacker can send an oversized request to corrupt memory and potentially execute arbitrary code on the server. The flaw is in an old, likely unsupported web server, so exposure depends on whether the product is still deployed.
Impact
Successful exploitation can allow an attacker to execute arbitrary code with the privileges of the web server process, leading to full compromise of the host. Even without reliable code execution, the overflow can crash the service and cause denial of service.
Attack surface
The vulnerability is reached over the network through the HTTP service, as indicated by the AV:N vector, and requires no authentication or user interaction. Any host running the affected Savant Web Server and reachable on its listening port is exposed.
Exploitation
The record is not listed in CISA KEV, but EPSS is high at 0.66593 (99.25th percentile), and a public Exploit-DB entry exists, indicating exploit code is available. No ransomware association is documented.
What to do
- Upgrade to a patched version of Savant Web Server or, if no supported fix exists, migrate to a maintained web server.
- If the product cannot be replaced, restrict network access to the HTTP service using firewall rules or a reverse proxy.
- Run the web server with least privilege and in a segregated network segment to limit the impact of code execution.
- Monitor vendor and advisory references for a patch and apply it as soon as it is available.
Detection
- Inspect HTTP server logs for unusually long GET request lines or malformed request URIs targeting the Savant service.
- Monitor for crashes or restarts of the Savant Web Server process that correlate with inbound HTTP traffic.
- Use network IDS/IPS signatures for buffer overflow attempts against Savant Web Server if available.
- Watch for unexpected child processes or outbound connections originating from the web server host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://archives.neohapsis.com/archives/vulnwatch/2002-q3/0112.html | PatchVendor Advisory |
| http://www.iss.net/security_center/static/10076.php | Vendor Advisory |
| http://www.securityfocus.com/bid/5686 | Vendor Advisory |
| https://www.exploit-db.com/exploits/16770/ | |
| http://archives.neohapsis.com/archives/vulnwatch/2002-q3/0112.html | PatchVendor Advisory |
| http://www.iss.net/security_center/static/10076.php | Vendor Advisory |
| http://www.securityfocus.com/bid/5686 | Vendor Advisory |
| https://www.exploit-db.com/exploits/16770/ |
Track CVE-2002-1120 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2002-1120), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.