CVE-2002-1358

CRITICAL

Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as d...

Affects 7 products across 7 vendors.

BCS7.78
CVSS 2.010.0
EPSS5.8%
Percentile92th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
CWE Weakness Definitions
CWE-20: Improper Input Validation

Software does not validate or incorrectly validates input, allowing attackers to craft data processed in unintended ways.

Related Attack Patterns (CAPEC)
CAPEC-3 Using Leading 'Ghost' Character Sequences to Bypass Input Filters
via CWE-20
CAPEC-7 Blind SQL Injection
via CWE-20
CAPEC-8 Buffer Overflow in an API Call
via CWE-20
CAPEC-9 Buffer Overflow in Local Command-Line Utilities
via CWE-20
CAPEC-10 Buffer Overflow via Environment Variables
via CWE-20
Show all 51
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

This vulnerability was disclosed in 2002. A critical vulnerability affects Cisco systems (CVE-2002-1358). No public exploit code is currently available. Isolate affected systems if patching is not feasible.

BSID: BS-2002-GLOBAL-351445-C • Model: rule-based-v1 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2002-1358?
This vulnerability was disclosed in 2002. A critical vulnerability affects Cisco systems (CVE-2002-1358). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
What is the CVSS score for CVE-2002-1358?
CVE-2002-1358 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 5.8%.
Is CVE-2002-1358 actively exploited?
No confirmed active exploitation of CVE-2002-1358 as of 2026-05-30.
How do I remediate CVE-2002-1358?
Priority: MEDIUM.
What systems are affected by CVE-2002-1358?
CVE-2002-1358 affects: Cisco, Fissh, Intersoft, Netcomposite, Pragma Systems, Putty, Winscp.
Vulnerability Details
CVE IDCVE-2002-1358
BSIDBS-2002-GLOBAL-351445-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2002-12-23
Last Modified2026-04-16
ICS Relevance55%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite. CVSS vector: AV:N/AC:L/Au:N/C:C/I:C/A:C.

Exploitation Likelihood: LOW

Affected Products
VendorProductFixed Version
Cisco Ios
Fissh Ssh Client
Intersoft Securenetterm
Netcomposite Shellguard Ssh
Pragma Systems Secureshell
Putty Putty
Winscp Winscp
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 8625 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hashd46a9eb73c0c326252e1ba71191697a644654c79f2f011426947640ef920943533097ef54e5f87882e1c24980113e760a8dc45a1192d4dc11b1f711d5028624e
Related CVEs affecting Cisco
CVE-2008-0529 10.0 Buffer overflow in the telnet server in Cisco Unified IP Phone 7906G, 7911G, ... CVE-2008-0029 10.0 Cisco Application Velocity System (AVS) before 5.1.0 is installed with defaul... CVE-2014-0659 10.0 The Cisco WAP4410N access point with firmware through 2.0.6.1, WRVS4400N rout... CVE-2014-0648 10.0 The RMI interface in Cisco Secure Access Control System (ACS) 5.x before 5.5 ... CVE-2011-0364 10.0 The Management Console (webagent.exe) in Cisco Security Agent 5.1, 5.2, and 6...
View all Cisco CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →