PT-2005-3651 · Wrq · Wrq Reflection For Secure It Windows Server

Publicado

2005-09-02

·

Atualizado

2008-09-05

·

CVE-2005-2770

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions WRQ Reflection for Secure IT Windows Server version 6.0
Description The issue arises when the Windows Administrator or Guest accounts are renamed after SSH key authentication has been configured. This allows remote attackers to use the original names during login.
Recommendations For WRQ Reflection for Secure IT Windows Server version 6.0, consider disabling SSH key authentication until a proper fix is applied to handle renamed Administrator or Guest accounts correctly. As a temporary workaround, restrict access to the server to minimize the risk of exploitation by only allowing connections from trusted sources. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-2770

Produtos afetados

Wrq Reflection For Secure It Windows Server