{"api_version":"1","generated_at":"2026-07-23T09:33:46+00:00","cve":"CVE-2005-2770","urls":{"html":"https://cve.report/CVE-2005-2770","api":"https://cve.report/api/cve/CVE-2005-2770.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-2770","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-2770"},"summary":{"title":"CVE-2005-2770","description":"WRQ Reflection for Secure IT Windows Server 6.0 (formerly known as F-Secure SSH server) does not properly handle when the Windows Administrator or Guest accounts are renamed after SSH key authentication has been configured, which allows remote attackers to use the original names during login.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-09-02 23:03:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.kb.cert.org/vuls/id/902110","name":"http://www.kb.cert.org/vuls/id/902110","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"],"title":"US-CERT Vulnerability Note VU#902110","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1014835","name":"http://securitytracker.com/id?1014835","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Reflection for Secure IT Multiple Bugs May Let Local Users Obtain Host Keys or Let Remote Users Access Certain Accounts or Systems - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/16649/","name":"http://secunia.com/advisories/16649/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Secunia - Advisories - WRQ Reflection for Secure IT Windows Server Multiple Security Issues","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://support.wrq.com/techdocs/1910.html","name":"http://support.wrq.com/techdocs/1910.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-2770","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-2770","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"2770","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"wrq","cpe5":"wrq_reflection_for_secure_it_windows_server","cpe6":"6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T22:45:02.252Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"1014835","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1014835"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.wrq.com/techdocs/1910.html"},{"name":"VU#902110","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/902110"},{"name":"16649","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/16649/"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-08-31T00:00:00.000Z","descriptions":[{"lang":"en","value":"WRQ Reflection for Secure IT Windows Server 6.0 (formerly known as F-Secure SSH server) does not properly handle when the Windows Administrator or Guest accounts are renamed after SSH key authentication has been configured, which allows remote attackers to use the original names during login."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2005-09-09T09:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"1014835","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1014835"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.wrq.com/techdocs/1910.html"},{"name":"VU#902110","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/902110"},{"name":"16649","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/16649/"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-2770","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"WRQ Reflection for Secure IT Windows Server 6.0 (formerly known as F-Secure SSH server) does not properly handle when the Windows Administrator or Guest accounts are renamed after SSH key authentication has been configured, which allows remote attackers to use the original names during login."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"1014835","refsource":"SECTRACK","url":"http://securitytracker.com/id?1014835"},{"name":"http://support.wrq.com/techdocs/1910.html","refsource":"CONFIRM","url":"http://support.wrq.com/techdocs/1910.html"},{"name":"VU#902110","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/902110"},{"name":"16649","refsource":"SECUNIA","url":"http://secunia.com/advisories/16649/"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-2770","datePublished":"2005-09-02T04:00:00.000Z","dateReserved":"2005-09-02T00:00:00.000Z","dateUpdated":"2024-08-07T22:45:02.252Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-09-02 23:03:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:wrq:wrq_reflection_for_secure_it_windows_server:6.0:*:*:*:*:*:*:*","matchCriteriaId":"C286A86C-A95A-4AAC-A83F-D144D881849F"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"2770","Ordinal":"1","Title":"CVE-2005-2770","CVE":"CVE-2005-2770","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"2770","Ordinal":"1","NoteData":"WRQ Reflection for Secure IT Windows Server 6.0 (formerly known as F-Secure SSH server) does not properly handle when the Windows Administrator or Guest accounts are renamed after SSH key authentication has been configured, which allows remote attackers to use the original names during login.","Type":"Description","Title":"CVE-2005-2770"},{"CveYear":"2005","CveId":"2770","Ordinal":"2","NoteData":"2005-09-02","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"2770","Ordinal":"3","NoteData":"2005-09-09","Type":"Other","Title":"Modified"}]}}}