CVE-2002-1358
published 2002-12-23CVE-2002-1358: Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a denial of service or…
PriorityP428critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.84%
92.4th percentile
Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| debian | openssh | — | — |
| fissh | ssh_client | — | — |
| intersoft | securenetterm | — | — |
| netcomposite | shellguard_ssh | — | — |
| pragma_systems | secureshell | — | — |
| putty | putty | — | — |
| putty | putty | — | — |
| putty | putty | — | — |
| winscp | winscp | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_debian10.0LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
SSH Malformed Packet Vulnerabilities
vendor_cisco·2002-12-19
CVE-2002-1357 SSH Malformed Packet Vulnerabilities
SSH Malformed Packet Vulnerabilities
Certain Cisco products containing support for the Secure Shell (SSH)
server are vulnerable to a Denial of Service (DoS) if the SSH server is enabled
on the device. A malformed SSH packet directed at the affected device can cause
a reload of the device. No authentication is necessary for the packet to be
received by the affected device. The SSH server in Cisco IOS® is disabled by
default.
Cisco will be making free software available to correct the problem as
soon as possible.
The malformed packets can be generated using the SSHredder test suite
from Rapid7, Inc. Workarounds are
available. The Cisco PSIRT is not aware of any malicious exploitation of this
vulnerability.
This advisory is available at
https://sec.cloudapps.cisco.com/security/center/conte
Debian
CVE-2002-1358: openssh - Multiple SSH2 servers and clients do not properly handle lists with empty elemen...
vendor_debian·2002·CVSS 10.0
CVE-2002-1358 [CRITICAL] CVE-2002-1358: openssh - Multiple SSH2 servers and clients do not properly handle lists with empty elemen...
Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Cisco
SSH Malformed Packet Vulnerabilities
vendor_cisco
CVE-2002-1358 SSH Malformed Packet Vulnerabilities
CVE-2002-1358: SSH Malformed Packet Vulnerabilities
Certain Cisco products containing support for the Secure Shell (SSH) server are vulnerable to a Denial of Service (DoS) if the SSH server is enabled on the device. A malformed SSH packet directed at the affected device can cause a reload of the device. No authentication is necessary for the packet to be received by the affected device. The SSH server in Cisco IOS� is disabled by default. Cisco will be making free software available to correct the problem as soon as possible. The malformed packets can be generated using the SSHredder test suite from Rapid7, Inc.
Bug IDs: CSCdz60229, CSCdy87221, CSCdu75477, CSCdz62330, CSCdz66748
GHSA
GHSA-44gh-mpm8-5jhq: Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a denial of s
ghsa_unreviewed·2022-04-30
CVE-2002-1358 [HIGH] CWE-20 GHSA-44gh-mpm8-5jhq: Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a denial of s
Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.
No detection rules found.
http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0110.htmlhttp://securitytracker.com/id?1005812http://securitytracker.com/id?1005813http://www.cert.org/advisories/CA-2002-36.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5721http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0110.htmlhttp://securitytracker.com/id?1005812http://securitytracker.com/id?1005813http://www.cert.org/advisories/CA-2002-36.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5721
2002-12-23
Published