First published: Fri Sep 02 2005(Updated: )
WRQ Reflection for Secure IT Windows Server 6.0 (formerly known as F-Secure SSH server) does not properly handle when the Windows Administrator or Guest accounts are renamed after SSH key authentication has been configured, which allows remote attackers to use the original names during login.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Attachmate Reflection for Secure IT | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2770 is considered a medium severity vulnerability due to its potential for unauthorized access.
To fix CVE-2005-2770, ensure that SSH key authentication is configured under accounts that have not been renamed.
CVE-2005-2770 exploits the improper handling of renamed Windows Administrator or Guest accounts in SSH key authentication.
CVE-2005-2770 affects users of WRQ Reflection for Secure IT Windows Server version 6.0.
The potential consequences of CVE-2005-2770 include unauthorized remote access using original account names.