PT-2005-3651 · Wrq · Wrq Reflection For Secure It Windows Server

Published

2005-09-02

·

Updated

2008-09-05

·

CVE-2005-2770

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions WRQ Reflection for Secure IT Windows Server version 6.0
Description The issue arises when the Windows Administrator or Guest accounts are renamed after SSH key authentication has been configured. This allows remote attackers to use the original names during login.
Recommendations For WRQ Reflection for Secure IT Windows Server version 6.0, consider disabling SSH key authentication until a proper fix is applied to handle renamed Administrator or Guest accounts correctly. As a temporary workaround, restrict access to the server to minimize the risk of exploitation by only allowing connections from trusted sources. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-2770

Affected Products

Wrq Reflection For Secure It Windows Server