Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-chcm-jqp3-j5w3

Опубликовано: 18 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 7.5
CVSS3: 6.2

Описание

BullWall Server Intrusion Protection services are initialized after login services. An authenticated attacker with administrative permissions can log in after boot and bypass MFA. SIP service does not retroactively enforce the challenge or disconnect unauthenticated sessions. Versions 4.6.0.0, 4.6.0.6, 4.6.0.7, and 4.6.1.4 were confirmed to be affected; other versions before and after may also be affected.

BullWall Server Intrusion Protection services are initialized after login services. An authenticated attacker with administrative permissions can log in after boot and bypass MFA. SIP service does not retroactively enforce the challenge or disconnect unauthenticated sessions. Versions 4.6.0.0, 4.6.0.6, 4.6.0.7, and 4.6.1.4 were confirmed to be affected; other versions before and after may also be affected.

EPSS

Процентиль: 15%
0.00049
Низкий

7.5 High

CVSS4

6.2 Medium

CVSS3

Дефекты

CWE-367

Связанные уязвимости

CVSS3: 7.5
nvd
около 2 месяцев назад

BullWall Server Intrusion Protection (SIP) services are initialized after login services during system startup. A local, authenticated attacker can log in after boot and before SIP MFA is running. The SIP services do not retroactively enforce MFA or disconnect sessions that were not subject to SIP MFA. Versions 4.6.0.0, 4.6.0.6, 4.6.0.7, and 4.6.1.4 are affected. Other versions mayy also be affected. BullWall plans to improve detection method documentation.

EPSS

Процентиль: 15%
0.00049
Низкий

7.5 High

CVSS4

6.2 Medium

CVSS3

Дефекты

CWE-367