← Vulnerability feed

Vulnerability record · CVE-2002-1359 · published 23 December 2002

CVE-2002-1359: SSH2 implementations mishandle large packets, enabling DoS and possible code execution

Cisco · Ios

Multiple SSH2 servers and clients fail to properly handle large packets or large fields, leading to buffer overflow conditions. The flaw was demonstrated by the SSHredder SSH protocol test suite and affects a range of SSH implementations across vendors. Because SSH is a core remote-access protocol, a flaw in packet handling can expose both clients and servers.

10.0 CVSS 2.0 High EPSS 80% · top 0.4% CWE-20 · Improper input validation
10.0CVSS 2.0 base score
80%EPSS exploitation probability, 30 days
NoNot in CISA KEV
7Affected product versions listed by NVD
14References
16 Jun 2026Last modified by NVD

Description

Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code via buffer overflow attacks, as demonstrated by the SSHredder SSH protocol test suite.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityThe CVSS 2.0 score is 10.0 with network reachability and no authentication, and EPSS is at the 99.6th percentile, though KEV listing and confirmed exploitation are absent.

What it is

Multiple SSH2 servers and clients fail to properly handle large packets or large fields, leading to buffer overflow conditions. The flaw was demonstrated by the SSHredder SSH protocol test suite and affects a range of SSH implementations across vendors. Because SSH is a core remote-access protocol, a flaw in packet handling can expose both clients and servers.

Impact

A remote attacker can cause a denial of service, and the record states arbitrary code execution is possible via buffer overflow. The CVSS 2.0 vector rates full confidentiality, integrity and availability impact.

Attack surface

Reachable over the network (AV:N) with no authentication (Au:N) and low complexity (AC:L), based on the CVSS vector. No user interaction is indicated in the record.

Exploitation

Not listed in CISA KEV and no ransomware usage is documented. EPSS is very high (0.80233, 99.6th percentile), but the record contains no reference tagged as an exploit, so active exploitation is not confirmed by the supplied data.

What to do

  • Apply vendor patches or upgrades for the affected SSH2 servers and clients (Cisco IOS, PuTTY, WinSCP, F-Secure, Intersoft, NetComposite, Pragma Systems, and others listed).
  • If patching is not immediately possible, restrict SSH access to trusted networks and disable unnecessary SSH services.
  • Enforce SSH protocol version and packet-size limits where the implementation allows configuration.
  • Monitor vendor and CERT/CC advisory CA-2002-36 for updated guidance and affected product lists.
  • Inventory SSH clients and servers in use to identify unpatched implementations.

Detection

  • Monitor SSH daemons and clients for crashes, abnormal termination or restarts that could indicate malformed large-packet handling.
  • Inspect network traffic for oversized or malformed SSH packets, particularly during protocol negotiation.
  • Correlate host logs for repeated SSH connection failures or memory-related errors on SSH processes.
  • Watch for unexpected process behavior or code execution on hosts running affected SSH implementations.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2002-1359 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-0171Cisco IOS Smart Install improper input validation allows remote code executionCisco IOS and IOS XE Smart Install fails to properly validate packet data, so a crafted Smart Install message sent to TCP port 4786 can overflow a bu…KEVEPSS 99%analysed9.8CVE-2017-12240Cisco IOS and IOS XE DHCP Relay Buffer Overflow RCEThe DHCP relay subsystem in Cisco IOS 12.2 through 15.6 and Cisco IOS XE contains a buffer overflow caused by improper input validation of DHCPv4 pac…KEVEPSS 14%analysed9.8CVE-2017-3881Cisco IOS/IOS XE CMP Telnet Option Handling RCECisco IOS and IOS XE fail to restrict CMP-specific Telnet options to internal cluster communications and mishandle malformed CMP Telnet options, so a…KEVEPSS 99%analysed8.8CVE-2018-0167Cisco IOS, IOS XE and IOS XR LLDP buffer overflowMultiple buffer overflow flaws exist in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE and IOS XR Software. An unauthenticat…KEVEPSS 3.4%analysed8.8CVE-2017-6736Cisco IOS and IOS XE SNMP buffer overflow remote code executionThe SNMP subsystem in Cisco IOS and IOS XE contains a buffer overflow that can be triggered by a crafted SNMP packet sent over IPv4 or IPv6. It affec…KEVEPSS 70%analysed8.8CVE-2017-6737Cisco IOS and IOS XE SNMP Buffer Overflow RCECisco IOS and IOS XE contain a buffer overflow in the SNMP implementation that affects SNMPv1, v2c, and v3. An authenticated remote attacker who know…KEVEPSS 45%analysed8.8CVE-2017-6738Cisco IOS and IOS XE SNMP buffer overflow allows remote code executionThe SNMP subsystem in Cisco IOS and IOS XE Software contains a buffer overflow that affects SNMP versions 1, 2c, and 3. An authenticated remote attac…KEVEPSS 11%analysed8.8CVE-2017-6739Cisco IOS and IOS XE SNMP buffer overflow allows remote code executionCisco IOS and IOS XE contain a buffer overflow in the SNMP implementation that affects SNMP versions 1, 2c, and 3. A remote attacker who knows the SN…KEVEPSS 11%analysed

Source: NIST National Vulnerability Database (record CVE-2002-1359), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.