7.7
CVE-2025-62003
- EPSS 0.34%
- Veröffentlicht 18.12.2025 20:35:52
- Zuletzt bearbeitet 15.01.2026 20:16:04
- CVE-Watchlists
- Unerledigt
BullWall Server Intrusion Protection RDP MFA connection delay
BullWall Server Intrusion Protection has a noticeable configuration-dependent delay before the MFA check for RDP connections. A remote, authenticated attacker can potentially bypass detection during this delay. Versions 4.6.0.0, 4.6.0.6, 4.6.0.7, and 4.6.1.4 are affected. Other versions may also be affected.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bullwall ≫ Server Intrusion Protection Version4.6.0.0
Bullwall ≫ Server Intrusion Protection Version4.6.0.6
Bullwall ≫ Server Intrusion Protection Version4.6.0.7
Bullwall ≫ Server Intrusion Protection Version4.6.1.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.34% | 0.274 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| cisa-cg | 7.7 | 0 | 0 |
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| cisa-cg | 7.5 | 1.6 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition
The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.
https://www.cve.org/CVERecord?id=CVE-2025-62003
https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-352-01.json