PT-2005-3652 · Wrq · Wrq Reflection For Secure It Windows Server
Published
2005-09-02
·
Updated
2008-09-05
·
CVE-2005-2771
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
WRQ Reflection for Secure IT Windows Server version 6.0
Description
The software processes access and deny lists in a case-sensitive manner, which could allow remote attackers to bypass intended restrictions and login to accounts that should be denied, as previous versions were case-insensitive.
Recommendations
For version 6.0, consider temporarily restricting access to sensitive accounts until a configuration or update can be applied to handle access and deny lists in a case-insensitive manner.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wrq Reflection For Secure It Windows Server