Pragma Systems maintains a narrow portfolio of remote-access and terminal-server products, including SecureShell, Telnet servers, and SSH implementations that serve connectivity functions in legacy and specialized network environments. The vendor's vulnerability exposure recurs through input-validation and memory-buffer-handling weaknesses characteristic of network protocol parsing, and public exploit code has frequently been developed for disclosed issues. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pragma Systems over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-1359HIGH Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial of service or possibly execute arbitrary | Dec 23, 2002 | 10.0 | 85 | NO | YES |
CVE-2002-1357HIGH Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote attackers to cause a denial of service or | Dec 23, 2002 | 10.0 | 35 | NO | NO |
CVE-2002-1358HIGH Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a denial of service or possibly execute arb | Dec 23, 2002 | 10.0 | 33 | NO | NO |
CVE-2008-0153MEDIUM telnetd.exe in Pragma TelnetServer 7.0.4.589 allows remote attackers to cause a denial of service (process crash and resource exhaustion) via a crafted TELOPT PRAGMA LOGON telnet o | Jan 9, 2008 | 5.0 | 32 | NO | YES |
CVE-2002-1360HIGH Multiple SSH2 servers and clients do not properly handle strings with null characters in them when the string length is specified by a length field, which could allow remote attack | Dec 23, 2002 | 10.0 | 29 | NO | NO |
CVE-2001-1263MEDIUM telnet95.exe in Pragma InterAccess 4.0 build 5 allows remote attackers to cause a denial of service (crash) via a large number of characters to port 23, possibly due to a buffer ov | Jun 6, 2001 | 5.0 | 27 | NO | YES |
CVE-2000-0708MEDIUM Buffer overflow in Pragma Systems TelnetServer 2000 version 4.0 allows remote attackers to cause a denial of service via a long series of null characters to the rexec port. | Oct 20, 2000 | 5.0 | 27 | NO | YES |
CVE-2000-0212MEDIUM InterAccess TelnetD Server 4.0 allows remote attackers to conduct a denial of service via malformed terminal client configuration information. | Feb 24, 2000 | 5.0 | 24 | NO | YES |
CVE-2006-2421HIGH Stack-based buffer overflow in Pragma FortressSSH 4.0.7.20 allows remote attackers to execute arbitrary code via long SSH_MSG_KEXINIT messages, which may cause an overflow when bei | May 17, 2006 | 7.5 | 20 | NO | NO |
CVE-2005-1969MEDIUM Cross-site scripting (XSS) vulnerability in Pragma Systems Telnetserver 6.0 allows remote attackers to inject arbitrary web script or HTML, and hide activities in log files, via a | Jun 7, 2005 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pragma Systems.
Media articles that mention a CVE ID that affects a product developed by Pragma Systems — matched by CVE ID, not by vendor name.