Vulnerability record · CVE-2002-1359 · published 23 December 2002
CVE-2002-1359: SSH2 implementations mishandle large packets, enabling DoS and possible code execution
Cisco · Ios
Multiple SSH2 servers and clients fail to properly handle large packets or large fields, leading to buffer overflow conditions. The flaw was demonstrated by the SSHredder SSH protocol test suite and affects a range of SSH implementations across vendors. Because SSH is a core remote-access protocol, a flaw in packet handling can expose both clients and servers.
Description
Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code via buffer overflow attacks, as demonstrated by the SSHredder SSH protocol test suite.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityThe CVSS 2.0 score is 10.0 with network reachability and no authentication, and EPSS is at the 99.6th percentile, though KEV listing and confirmed exploitation are absent.
What it is
Multiple SSH2 servers and clients fail to properly handle large packets or large fields, leading to buffer overflow conditions. The flaw was demonstrated by the SSHredder SSH protocol test suite and affects a range of SSH implementations across vendors. Because SSH is a core remote-access protocol, a flaw in packet handling can expose both clients and servers.
Impact
A remote attacker can cause a denial of service, and the record states arbitrary code execution is possible via buffer overflow. The CVSS 2.0 vector rates full confidentiality, integrity and availability impact.
Attack surface
Reachable over the network (AV:N) with no authentication (Au:N) and low complexity (AC:L), based on the CVSS vector. No user interaction is indicated in the record.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented. EPSS is very high (0.80233, 99.6th percentile), but the record contains no reference tagged as an exploit, so active exploitation is not confirmed by the supplied data.
What to do
- Apply vendor patches or upgrades for the affected SSH2 servers and clients (Cisco IOS, PuTTY, WinSCP, F-Secure, Intersoft, NetComposite, Pragma Systems, and others listed).
- If patching is not immediately possible, restrict SSH access to trusted networks and disable unnecessary SSH services.
- Enforce SSH protocol version and packet-size limits where the implementation allows configuration.
- Monitor vendor and CERT/CC advisory CA-2002-36 for updated guidance and affected product lists.
- Inventory SSH clients and servers in use to identify unpatched implementations.
Detection
- Monitor SSH daemons and clients for crashes, abnormal termination or restarts that could indicate malformed large-packet handling.
- Inspect network traffic for oversized or malformed SSH packets, particularly during protocol negotiation.
- Correlate host logs for repeated SSH connection failures or memory-related errors on SSH processes.
- Watch for unexpected process behavior or code execution on hosts running affected SSH implementations.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2002-1359 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2002-1359), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.