ID

VAR-200303-0039


CVE

CVE-2002-1547


TITLE

NetScreen Secure Command Shell (SCS) denial-of-service vulnerability

Trust: 0.8

sources: CERT/CC: VU#930161

DESCRIPTION

Netscreen running ScreenOS 4.0.0r6 and earlier allows remote attackers to cause a denial of service via a malformed SSH packet to the Secure Command Shell (SCS) management interface, as demonstrated via certain CRC32 exploits, a different vulnerability than CVE-2001-0144. The Secure Command Shell service on NetScreen firewall products contains a remotely exploitable denial-of-service vulnerability. The vulnerability exists in Netscreen running ScreenOS 4.0.0r6 and earlier

Trust: 1.71

sources: NVD: CVE-2002-1547 // CERT/CC: VU#930161 // VULHUB: VHN-5932

AFFECTED PRODUCTS

vendor:junipermodel:netscreen screenosscope:lteversion:4.0.0r6

Trust: 1.0

vendor:netscreenmodel: - scope: - version: -

Trust: 0.8

vendor:junipermodel:netscreen screenosscope:eqversion:4.0.0r6

Trust: 0.6

sources: CERT/CC: VU#930161 // CNNVD: CNNVD-200303-090 // NVD: CVE-2002-1547

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2002-1547
value: MEDIUM

Trust: 1.0

CARNEGIE MELLON: VU#930161
value: 5.40

Trust: 0.8

CNNVD: CNNVD-200303-090
value: MEDIUM

Trust: 0.6

VULHUB: VHN-5932
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2002-1547
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-5932
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CERT/CC: VU#930161 // VULHUB: VHN-5932 // CNNVD: CNNVD-200303-090 // NVD: CVE-2002-1547

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2002-1547

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200303-090

TYPE

unknown

Trust: 0.6

sources: CNNVD: CNNVD-200303-090

EXTERNAL IDS

db:CERT/CCid:VU#930161

Trust: 2.5

db:OSVDBid:4376

Trust: 1.7

db:NVDid:CVE-2002-1547

Trust: 1.7

db:CNNVDid:CNNVD-200303-090

Trust: 0.7

db:VULNWATCHid:20021101 NETSCREEN SSH1 CRC32 COMPENSATION DENIAL OF SERVICE

Trust: 0.6

db:VULNWATCHid:20021101 (CORRECTION) NETSCREEN SSH1 CRC32 COMPENSATION DENIAL OF SERVICE

Trust: 0.6

db:XFid:10528

Trust: 0.6

db:BUGTRAQid:20021101 NETSCREEN SSH1 CRC32 COMPENSATION DENIAL OF SERVICE

Trust: 0.6

db:BUGTRAQid:20021101 (CORRECTION) NETSCREEN SSH1 CRC32 COMPENSATION DENIAL OF SERVICE

Trust: 0.6

db:VULHUBid:VHN-5932

Trust: 0.1

sources: CERT/CC: VU#930161 // VULHUB: VHN-5932 // CNNVD: CNNVD-200303-090 // NVD: CVE-2002-1547

REFERENCES

url:http://www.netscreen.com/support/alerts/11_06_02.html

Trust: 2.5

url:http://archives.neohapsis.com/archives/bugtraq/2002-10/0446.html

Trust: 1.7

url:http://archives.neohapsis.com/archives/bugtraq/2002-10/0443.html

Trust: 1.7

url:http://www.kb.cert.org/vuls/id/930161

Trust: 1.7

url:http://www.osvdb.org/4376

Trust: 1.7

url:http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0054.html

Trust: 1.7

url:http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0053.html

Trust: 1.7

url:http://www.iss.net/security_center/static/10528.php

Trust: 1.7

url:http://online.securityfocus.com/archive/1/298274

Trust: 0.8

url:http://online.securityfocus.com/archive/1/298288

Trust: 0.8

url:http://online.securityfocus.com/archive/1/298289

Trust: 0.8

sources: CERT/CC: VU#930161 // VULHUB: VHN-5932 // CNNVD: CNNVD-200303-090 // NVD: CVE-2002-1547

SOURCES

db:CERT/CCid:VU#930161
db:VULHUBid:VHN-5932
db:CNNVDid:CNNVD-200303-090
db:NVDid:CVE-2002-1547

LAST UPDATE DATE

2024-08-14T14:16:13.998000+00:00


SOURCES UPDATE DATE

db:CERT/CCid:VU#930161date:2002-12-10T00:00:00
db:VULHUBid:VHN-5932date:2008-09-05T00:00:00
db:CNNVDid:CNNVD-200303-090date:2006-08-23T00:00:00
db:NVDid:CVE-2002-1547date:2008-09-05T20:30:53.263

SOURCES RELEASE DATE

db:CERT/CCid:VU#930161date:2002-11-19T00:00:00
db:VULHUBid:VHN-5932date:2003-03-31T00:00:00
db:CNNVDid:CNNVD-200303-090date:2003-03-31T00:00:00
db:NVDid:CVE-2002-1547date:2003-03-31T05:00:00