BullWall Ransomware Containment considers the number of files modified to trigger detection. An authenticated attacker could encrypt a single (possibly large) file without triggering detection if thresholds are configured to require multiple file changes. The number of files to trigger detection can be configured by the user. Versions 4.6.0.0, 4.6.0.6, 4.6.0.7, and 4.6.1.4 are affected. Other versions may also be affected.
The product does not implement or incorrectly implements one or more security-relevant checks as specified by the design of a standardized algorithm, protocol, or technique.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Ransomware_containment | Bullwall | 4.6.0.0 (including) | 4.6.0.0 (including) |
| Ransomware_containment | Bullwall | 4.6.0.6 (including) | 4.6.0.6 (including) |
| Ransomware_containment | Bullwall | 4.6.0.7 (including) | 4.6.0.7 (including) |
| Ransomware_containment | Bullwall | 4.6.1.4 (including) | 4.6.1.4 (including) |