CVE-2025-62003

HIGH

BullWall Server Intrusion Protection 4.6.0.0 4.6.0.6 4.6.0.7 4.6.1.4 - Authenticated MFA Bypass via RDP Connection Delay

Title source: llm
STIX 2.1

Description

BullWall Server Intrusion Protection has a noticeable configuration-dependent delay before the MFA check for RDP connections. A remote, authenticated attacker can potentially bypass detection during this delay. Versions 4.6.0.0, 4.6.0.6, 4.6.0.7, and 4.6.1.4 are affected. Other versions may also be affected.

References (2)

Core 2
Core References
Third Party Advisory vdb-entry
https://www.cve.org/CVERecord?id=CVE-2025-62003

Scores

CVSS v3 7.5
EPSS 0.0031
EPSS Percentile 22.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-367
Status published
Products (4)
bullwall/server_intrusion_protection 4.6.0.0
bullwall/server_intrusion_protection 4.6.0.6
bullwall/server_intrusion_protection 4.6.0.7
bullwall/server_intrusion_protection 4.6.1.4
Published Dec 18, 2025
Tracked Since Feb 18, 2026