CVE-2025-62003

BullWall Server Intrusion Protection has a noticeable configuration-dependent delay before the MFA check for RDP connections. A remote, authenticated attacker can potentially bypass detection during this delay. Versions 4.6.0.0, 4.6.0.6, 4.6.0.7, and 4.6.1.4 are affected. Other versions may also be affected.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:bullwall:server_intrusion_protection:4.6.0.0:*:*:*:*:*:*:*
cpe:2.3:a:bullwall:server_intrusion_protection:4.6.0.6:*:*:*:*:*:*:*
cpe:2.3:a:bullwall:server_intrusion_protection:4.6.0.7:*:*:*:*:*:*:*
cpe:2.3:a:bullwall:server_intrusion_protection:4.6.1.4:*:*:*:*:*:*:*

History

15 Jan 2026, 20:16

Type Values Removed Values Added
Summary (en) BullWall Server Intrusion Protection has a noticeable configuration-dependent delay before the MFA check when connecting via RDP. A remote authenticated attacker with administrative privileges can potentially bypass detection during this window. Versions 4.6.0.0, 4.6.0.6, 4.6.0.7, and 4.6.1.4 were confirmed to be affected; other versions before and after may also be affected. (en) BullWall Server Intrusion Protection has a noticeable configuration-dependent delay before the MFA check for RDP connections. A remote, authenticated attacker can potentially bypass detection during this delay. Versions 4.6.0.0, 4.6.0.6, 4.6.0.7, and 4.6.1.4 are affected. Other versions may also be affected.
CVSS v2 : unknown
v3 : 6.6
v2 : unknown
v3 : 7.5

14 Jan 2026, 22:15

Type Values Removed Values Added
References
  • {'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/VA-25-352-01.json', 'tags': ['Broken Link'], 'source': '9119a7d8-5eab-497f-8521-727c672e3725'}
  • () https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-352-01.json - Broken Link
CVSS v2 : unknown
v3 : 6.2
v2 : unknown
v3 : 6.6
Summary (en) BullWall Server Intrusion Protection has a noticeable delay before the MFA check when connecting via RDP. A remote authenticated attacker with administrative privileges can potentially bypass detection during this window. Versions 4.6.0.0, 4.6.0.6, 4.6.0.7, and 4.6.1.4 were confirmed to be affected; other versions before and after may also be affected. (en) BullWall Server Intrusion Protection has a noticeable configuration-dependent delay before the MFA check when connecting via RDP. A remote authenticated attacker with administrative privileges can potentially bypass detection during this window. Versions 4.6.0.0, 4.6.0.6, 4.6.0.7, and 4.6.1.4 were confirmed to be affected; other versions before and after may also be affected.

12 Jan 2026, 17:15

Type Values Removed Values Added
References () https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/VA-25-352-01.json - () https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/VA-25-352-01.json - Broken Link
References () https://www.cve.org/CVERecord?id=CVE-2025-62003 - () https://www.cve.org/CVERecord?id=CVE-2025-62003 - Third Party Advisory
CPE cpe:2.3:a:bullwall:server_intrusion_protection:4.6.0.7:*:*:*:*:*:*:*
cpe:2.3:a:bullwall:server_intrusion_protection:4.6.0.0:*:*:*:*:*:*:*
cpe:2.3:a:bullwall:server_intrusion_protection:4.6.1.4:*:*:*:*:*:*:*
cpe:2.3:a:bullwall:server_intrusion_protection:4.6.0.6:*:*:*:*:*:*:*
First Time Bullwall server Intrusion Protection
Bullwall

18 Dec 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-18 21:15

Updated : 2026-01-15 20:16


NVD link : CVE-2025-62003

Mitre link : CVE-2025-62003

CVE.ORG link : CVE-2025-62003


JSON object : View

Products Affected

bullwall

  • server_intrusion_protection
CWE
CWE-367

Time-of-check Time-of-use (TOCTOU) Race Condition