CVE-2002-1646
Status: ModifiedHigh (7.5)—
SSH Secure Shell for Servers 3.0.0 to 3.1.1 allows remote attackers to override the AllowedAuthentications configuration and use less secure authentication schemes (e.g. password) than configured for the server.
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Base score: 7.5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 3.64%
- Percentile among all scored CVEs: 89
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- NVD-CWE-Other
References
- http://archives.neohapsis.com/archives/bugtraq/2002-05/0204.html
- http://www.ciac.org/ciac/bulletins/m-081.shtml
- http://www.kb.cert.org/vuls/id/341187
- http://www.securityfocus.com/bid/4810
- http://www.ssh.com/company/newsroom/article/201/
- http://www.ssh.com/products/ssh/advisories/authentication.cfm
- https://exchange.xforce.ibmcloud.com/vulnerabilities/9163
- http://archives.neohapsis.com/archives/bugtraq/2002-05/0204.html
- http://www.ciac.org/ciac/bulletins/m-081.shtml
- http://www.kb.cert.org/vuls/id/341187
- http://www.securityfocus.com/bid/4810
- http://www.ssh.com/company/newsroom/article/201/
- http://www.ssh.com/products/ssh/advisories/authentication.cfm
- https://exchange.xforce.ibmcloud.com/vulnerabilities/9163
Raw JSON (NVD)
Show
{
"id": "CVE-2002-1646",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2002-12-31T05:00:00.000",
"references": [
{
"url": "http://archives.neohapsis.com/archives/bugtraq/2002-05/0204.html",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.ciac.org/ciac/bulletins/m-081.shtml",
"source": "cve@mitre.org"
},
{
"url": "http://www.kb.cert.org/vuls/id/341187",
"tags": [
"US Government Resource"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/4810",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.ssh.com/company/newsroom/article/201/",
"source": "cve@mitre.org"
},
{
"url": "http://www.ssh.com/products/ssh/advisories/authentication.cfm",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/9163",
"source": "cve@mitre.org"
},
{
"url": "http://archives.neohapsis.com/archives/bugtraq/2002-05/0204.html",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.ciac.org/ciac/bulletins/m-081.shtml",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.kb.cert.org/vuls/id/341187",
"tags": [
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/4810",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.ssh.com/company/newsroom/article/201/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.ssh.com/products/ssh/advisories/authentication.cfm",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/9163",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "SSH Secure Shell for Servers 3.0.0 to 3.1.1 allows remote attackers to override the AllowedAuthentications configuration and use less secure authentication schemes (e.g. password) than configured for the server."
}
],
"lastModified": "2026-06-16T21:59:42.977",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ssh:secure_shell_for_servers:3.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0A1AD6B7-A164-49CD-A882-12C5D484CE9F"
},
{
"criteria": "cpe:2.3:a:ssh:secure_shell_for_servers:3.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1B20DF45-5EC3-4771-A589-B7264152BB7C"
},
{
"criteria": "cpe:2.3:a:ssh:secure_shell_for_servers:3.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "89B02880-2593-4071-B2E4-5AFC462A8CF5"
},
{
"criteria": "cpe:2.3:a:ssh:secure_shell_for_servers:3.1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "361B7BE0-4779-4692-8D7B-1B940E58BFA0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}