Description
BullWall Server Intrusion Protection has a noticeable delay before the MFA check when connecting via RDP. A remote authenticated attacker with administrative privileges can potentially bypass detection during this window. Versions 4.6.0.0, 4.6.0.6, 4.6.0.7, and 4.6.1.4 were confirmed to be affected; other versions before and after may also be affected.
Problem types
CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition
Product status
4.6.0.0 (custom) before *
Credits
Alexander Nikolaj Fischer
References
raw.githubusercontent.com/...IT/white/2025/va-25-352-01.json (url)
www.cve.org/CVERecord?id=CVE-2025-62003 (url)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.