AttachmateWRQ Reflection for Secure IT Windows Server Renamed Account Remote Login Vulnerability
BID:14733
Info
AttachmateWRQ Reflection for Secure IT Windows Server Renamed Account Remote Login Vulnerability
| Bugtraq ID: | 14733 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 25 2005 12:00AM |
| Updated: | Aug 25 2005 12:00AM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
AttachmateWRQ Reflection for Secure IT 6.0 |
| Not Vulnerable: | |
Discussion
AttachmateWRQ Reflection for Secure IT Windows Server Renamed Account Remote Login Vulnerability
AttachmateWRQ Reflection for Secure IT Windows Server is susceptible to a renamed account remote login vulnerability. This issue is due to a failure of the application to properly ensure that invalid accounts are not still accessible.
This vulnerability allows remote attackers to gain access to vulnerable computers, even if the targeted accounts are renamed in order to prevent further access.
It should be noted that remote attackers still require access to the private SSH key to exploit this vulnerability.
AttachmateWRQ Reflection for Secure IT Windows Server is susceptible to a renamed account remote login vulnerability. This issue is due to a failure of the application to properly ensure that invalid accounts are not still accessible.
This vulnerability allows remote attackers to gain access to vulnerable computers, even if the targeted accounts are renamed in order to prevent further access.
It should be noted that remote attackers still require access to the private SSH key to exploit this vulnerability.
Exploit / POC
AttachmateWRQ Reflection for Secure IT Windows Server Renamed Account Remote Login Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
AttachmateWRQ Reflection for Secure IT Windows Server Renamed Account Remote Login Vulnerability
Solution:
The vendor has released an advisory to address this issue. The advisory details the steps required to resolve this issue. Please see the referenced advisory for further information.
Solution:
The vendor has released an advisory to address this issue. The advisory details the steps required to resolve this issue. Please see the referenced advisory for further information.
References
AttachmateWRQ Reflection for Secure IT Windows Server Renamed Account Remote Login Vulnerability
References:
References: