CVE-2002-1359

Cisco IOS - Denial of Service via Large SSH Packet Handling

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2002-1359. PoCs published by Metasploit, y0, including Metasploit module exploits/windows/ssh/putty_msg_debug.

AI-analyzed exploit summary This is a Metasploit module exploiting a buffer overflow in PuTTY SSH client (CVE-2002-1359) via a malformed SSH protocol message. It targets Windows systems and delivers a payload to achieve remote code execution.

Description

Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code via buffer overflow attacks, as demonstrated by the SSHredder SSH protocol test suite.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16463

This is a Metasploit module exploiting a buffer overflow in PuTTY SSH client (CVE-2002-1359) via a malformed SSH protocol message. It targets Windows systems and delivers a payload to achieve remote code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: PuTTY.exe <= v0.53
No auth needed
Prerequisites: Network access to the target · Target using vulnerable PuTTY version
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by y0 · remotewindows
https://www.exploit-db.com/exploits/1788

This exploit targets a buffer overflow vulnerability in PuTTY SSH client versions up to 0.53. It sends a maliciously crafted SSH-2.0 banner to trigger the overflow, allowing arbitrary code execution on the target system.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: PuTTY.exe <= v0.53
No auth needed
Prerequisites: Network access to the target system · PuTTY client version <= 0.53
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC NORMAL
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/ssh/putty_msg_debug.rb

This Metasploit module exploits a buffer overflow in PuTTY SSH client (versions 0.53 and earlier) via a malformed SSH-2.0 banner. It triggers a stack-based overflow in SSH.c, allowing remote code execution on vulnerable Windows systems.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: PuTTY SSH client <= 0.53
No auth needed
Prerequisites: Network access to target · Vulnerable PuTTY version
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1005812
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert
http://www.cert.org/advisories/CA-2002-36.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/10870
Vendor Advisory mailing-list x_refsource_vulnwatch
http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0110.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/6407
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5848
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1005813

Scores

EPSS 0.7992
EPSS Percentile 99.6%

Details

CWE
CWE-20
Status published
Products (16)
cisco/ios 12.0s
cisco/ios 12.0st
cisco/ios 12.1e
cisco/ios 12.1ea
cisco/ios 12.1t
cisco/ios 12.2
cisco/ios 12.2s
cisco/ios 12.2t
fissh/ssh_client 1.0a_for_windows
intersoft/securenetterm 5.4.1
... and 6 more
Published Dec 23, 2002
Tracked Since Feb 18, 2026