Multiple SSH2 servers and clients do not properly handle strings with null characters in them when the string length is specified by a length field, which could allow remote attackers to cause a denial of service or possibly execute arbitrary code due to interactions with the use of null-terminated strings as implemented using languages such as C, as demonstrated by the SSHredder SSH protocol test suite.
Conclusion & alert: CVE-2002-1360 is rated High Risk (70.8/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 4.13%). Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-07-26 | 4.15% | 4.13% | -0.03% |
| 2 | 2025-03-30 | 13.38% | 4.15% | -9.22% |
| 3 | 2025-03-29 | — | 13.38% | — |
Full EPSS history (7 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 10.0 | 2.0 | HIGH |
|
10.0 | 10.0 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
unimportant | CVE-2002-1360 unimportant priority: Debian including 1 source packages (openssh), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2002-1360 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| cisco | ios | 12.0s | cpe:2.3:o:cisco:ios:12.0s:*:*:*:*:*:*:* |
| cisco | ios | 12.0st | cpe:2.3:o:cisco:ios:12.0st:*:*:*:*:*:*:* |
| cisco | ios | 12.1e | cpe:2.3:o:cisco:ios:12.1e:*:*:*:*:*:*:* |
| cisco | ios | 12.1ea | cpe:2.3:o:cisco:ios:12.1ea:*:*:*:*:*:*:* |
| cisco | ios | 12.1t | cpe:2.3:o:cisco:ios:12.1t:*:*:*:*:*:*:* |
| cisco | ios | 12.2 | cpe:2.3:o:cisco:ios:12.2:*:*:*:*:*:*:* |
| cisco | ios | 12.2s | cpe:2.3:o:cisco:ios:12.2s:*:*:*:*:*:*:* |
| cisco | ios | 12.2t | cpe:2.3:o:cisco:ios:12.2t:*:*:*:*:*:*:* |
| fissh | ssh_client | 1.0a_for_windows | cpe:2.3:a:fissh:ssh_client:1.0a_for_windows:*:*:*:*:*:*:* |
| intersoft | securenetterm | 5.4.1 | cpe:2.3:a:intersoft:securenetterm:5.4.1:*:*:*:*:*:*:* |
| netcomposite | shellguard_ssh | 3.4.6 | cpe:2.3:a:netcomposite:shellguard_ssh:3.4.6:*:*:*:*:*:*:* |
| pragma_systems | secureshell | 2.0 | cpe:2.3:a:pragma_systems:secureshell:2.0:*:*:*:*:*:*:* |
| putty | putty | 0.48 | cpe:2.3:a:putty:putty:0.48:*:*:*:*:*:*:* |
| putty | putty | 0.49 | cpe:2.3:a:putty:putty:0.49:*:*:*:*:*:*:* |
| putty | putty | 0.53 | cpe:2.3:a:putty:putty:0.53:*:*:*:*:*:*:* |
| winscp | winscp | 2.0.0 | cpe:2.3:a:winscp:winscp:2.0.0:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0110.html | Vendor Advisory |
| http://securitytracker.com/id?1005812 | |
| http://securitytracker.com/id?1005813 | |
| http://www.cert.org/advisories/CA-2002-36.html | Third Party Advisory US Government Resource |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5797 |