PT-2005-3651 · Wrq · Wrq Reflection For Secure It Windows Server
Published
2005-09-02
·
Updated
2008-09-05
·
CVE-2005-2770
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
WRQ Reflection for Secure IT Windows Server version 6.0
Description
The issue arises when the Windows Administrator or Guest accounts are renamed after SSH key authentication has been configured. This allows remote attackers to use the original names during login.
Recommendations
For WRQ Reflection for Secure IT Windows Server version 6.0, consider disabling SSH key authentication until a proper fix is applied to handle renamed Administrator or Guest accounts correctly. As a temporary workaround, restrict access to the server to minimize the risk of exploitation by only allowing connections from trusted sources. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wrq Reflection For Secure It Windows Server