CVE-2002-1357
published 2002-12-23CVE-2002-1357: Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote attackers to cause a…
PriorityP431critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
9.77%
95.0th percentile
Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| debian | openssh | — | — |
| fissh | ssh_client | — | — |
| intersoft | securenetterm | — | — |
| netcomposite | shellguard_ssh | — | — |
| pragma_systems | secureshell | — | — |
| putty | putty | — | — |
| putty | putty | — | — |
| putty | putty | — | — |
| winscp | winscp | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_debian10.0LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
SSH Malformed Packet Vulnerabilities
vendor_cisco·2002-12-19
CVE-2002-1357 SSH Malformed Packet Vulnerabilities
SSH Malformed Packet Vulnerabilities
Certain Cisco products containing support for the Secure Shell (SSH)
server are vulnerable to a Denial of Service (DoS) if the SSH server is enabled
on the device. A malformed SSH packet directed at the affected device can cause
a reload of the device. No authentication is necessary for the packet to be
received by the affected device. The SSH server in Cisco IOS® is disabled by
default.
Cisco will be making free software available to correct the problem as
soon as possible.
The malformed packets can be generated using the SSHredder test suite
from Rapid7, Inc. Workarounds are
available. The Cisco PSIRT is not aware of any malicious exploitation of this
vulnerability.
This advisory is available at
https://sec.cloudapps.cisco.com/security/center/conte
Debian
CVE-2002-1357: openssh - Multiple SSH2 servers and clients do not properly handle packets or data element...
vendor_debian·2002·CVSS 10.0
CVE-2002-1357 [CRITICAL] CVE-2002-1357: openssh - Multiple SSH2 servers and clients do not properly handle packets or data element...
Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Cisco
SSH Malformed Packet Vulnerabilities
vendor_cisco
CVE-2002-1357 SSH Malformed Packet Vulnerabilities
CVE-2002-1357: SSH Malformed Packet Vulnerabilities
Certain Cisco products containing support for the Secure Shell (SSH) server are vulnerable to a Denial of Service (DoS) if the SSH server is enabled on the device. A malformed SSH packet directed at the affected device can cause a reload of the device. No authentication is necessary for the packet to be received by the affected device. The SSH server in Cisco IOS� is disabled by default. Cisco will be making free software available to correct the problem as soon as possible. The malformed packets can be generated using the SSHredder test suite from Rapid7, Inc.
Bug IDs: CSCdz60229, CSCdy87221, CSCdu75477, CSCdz62330, CSCdz66748
GHSA
GHSA-2fjq-9whp-5fvh: Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote attackers t
ghsa_unreviewed·2022-04-30
CVE-2002-1357 [HIGH] CWE-119 GHSA-2fjq-9whp-5fvh: Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote attackers t
Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0110.htmlhttp://securitytracker.com/id?1005812http://securitytracker.com/id?1005813http://www.cert.org/advisories/CA-2002-36.htmlhttp://www.kb.cert.org/vuls/id/389665http://www.securityfocus.com/bid/6405https://exchange.xforce.ibmcloud.com/vulnerabilities/10868https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5849http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0110.htmlhttp://securitytracker.com/id?1005812http://securitytracker.com/id?1005813http://www.cert.org/advisories/CA-2002-36.htmlhttp://www.kb.cert.org/vuls/id/389665http://www.securityfocus.com/bid/6405https://exchange.xforce.ibmcloud.com/vulnerabilities/10868https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5849
2002-12-23
Published