Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-974m-5v9f-vwxw

Опубликовано: 18 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 7.5
CVSS3: 6.2

Описание

BullWall Server Intrusion Protection has a noticeable delay before the MFA check when connecting via RDP. A remote authenticated attacker with administrative privileges can potentially bypass detection during this window. Versions 4.6.0.0, 4.6.0.6, 4.6.0.7, and 4.6.1.4 were confirmed to be affected; other versions before and after may also be affected.

BullWall Server Intrusion Protection has a noticeable delay before the MFA check when connecting via RDP. A remote authenticated attacker with administrative privileges can potentially bypass detection during this window. Versions 4.6.0.0, 4.6.0.6, 4.6.0.7, and 4.6.1.4 were confirmed to be affected; other versions before and after may also be affected.

EPSS

Процентиль: 18%
0.00056
Низкий

7.5 High

CVSS4

6.2 Medium

CVSS3

Дефекты

CWE-367

Связанные уязвимости

CVSS3: 7.5
nvd
около 2 месяцев назад

BullWall Server Intrusion Protection has a noticeable configuration-dependent delay before the MFA check for RDP connections. A remote, authenticated attacker can potentially bypass detection during this delay. Versions 4.6.0.0, 4.6.0.6, 4.6.0.7, and 4.6.1.4 are affected. Other versions may also be affected.

EPSS

Процентиль: 18%
0.00056
Низкий

7.5 High

CVSS4

6.2 Medium

CVSS3

Дефекты

CWE-367