BullWall Server Intrusion Protection has a noticeable configuration-dependent delay before the MFA check for RDP connections. A remote, authenticated attacker can potentially bypass detection during this delay. Versions 4.6.0.0, 4.6.0.6, 4.6.0.7, and 4.6.1.4 are affected. Other versions may also be affected.
The product checks the state of a resource before using that resource, but the resource’s state can change between the check and the use in a way that invalidates the results of the check.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Server_intrusion_protection | Bullwall | 4.6.0.0 (including) | 4.6.0.0 (including) |
| Server_intrusion_protection | Bullwall | 4.6.0.6 (including) | 4.6.0.6 (including) |
| Server_intrusion_protection | Bullwall | 4.6.0.7 (including) | 4.6.0.7 (including) |
| Server_intrusion_protection | Bullwall | 4.6.1.4 (including) | 4.6.1.4 (including) |