CVE-2005-2771
WRQ Reflection for Secure IT Windows Server 6.0 (formerly known as F-Secure SSH server) processes access and deny lists in a case-sensitive manner, when previous versions were case-insensitive, which might allow remote attackers to bypass intended…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.85%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
WRQ Reflection for Secure IT Windows Server 6.0 (formerly known as F-Secure SSH server) processes access and deny lists in a case-sensitive manner, when previous versions were case-insensitive, which might allow remote attackers to bypass intended restrictions and login to accounts that should be denied.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 4.85% probability · 92th percentile
- CISA KEV
- Not listed
- Affected
- f-secure/f-secure ssh server · wrq/wrq reflection for secure it windows server
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/16649/Patch
- http://securitytracker.com/id?1014835
- http://support.wrq.com/techdocs/1910.html
- http://www.kb.cert.org/vuls/id/758054Third Party Advisory, US Government Resource
- http://secunia.com/advisories/16649/Patch
- http://securitytracker.com/id?1014835
- http://support.wrq.com/techdocs/1910.html
- http://www.kb.cert.org/vuls/id/758054Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.