Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2002-0639

41
FAUCET Score

CVE-2002-0639 describes a critical integer overflow vulnerability in OpenSSH versions 2.9.9 through 3.3. This flaw allows remote attackers to execute arbitrary code on affected systems during challenge-response authentication, specifically when SKEY or BSD_AUTH methods are in use. With a CVSS score of 9.8 (CRITICAL), it presents a severe risk due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. While no public exploit code or active exploitation has been confirmed, the vulnerability has garnered significant community discussion, indicating awareness and potential interest.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.9.9, <= 3.3CPE matchmatch criteria
cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
18.43%
Probability of exploitation in next 30 days
EPSS Percentile
96.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.1843 is in the 93rd percentile among its peer group of 36,835 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2002-0639

CVE-2002-0639

References

ftp.caldera.com / pub/security/OpenLinux/CSSA-2002-030.0.txt
Broken Link
archives.neohapsis.com / archives/bugtraq/2002-06/0335.html
Broken Link
distro.conectiva.com.br / atualizacoes
Broken Link
marc.info
ExploitMailing List
marc.info
ExploitMailing List
marc.info
ExploitMailing List
twitter.com / RooneyMcNibNug/status/1152332585349111810
Broken Link
web.archive.org / web/20080622172542/www.iss.net/threats/advise123.html
Third Party Advisory
www1.itrc.hp.com / service/cki/docDisplay.do
Broken Link
cert.org / advisories/CA-2002-18.html
Third Party AdvisoryUS Government Resource
debian.org / security/2002/dsa-134
Broken Link
iss.net / security_center/static/9169.php
Broken Link
kb.cert.org / vuls/id/369347
Third Party AdvisoryUS Government Resource
linuxsecurity.com / advisories/other_advisory-2177.html
Broken Link
mandrakesoft.com / security/advisories
Broken Link
osvdb.org / 6245
Broken Link
securityfocus.com / bid/5093
Broken LinkThird Party AdvisoryVDB Entry