CVE Vulnerabilities

CVE-2025-62003

Time-of-check Time-of-use (TOCTOU) Race Condition

Published: Dec 18, 2025 | Modified: Jan 15, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

BullWall Server Intrusion Protection has a noticeable configuration-dependent delay before the MFA check for RDP connections. A remote, authenticated attacker can potentially bypass detection during this delay. Versions 4.6.0.0, 4.6.0.6, 4.6.0.7, and 4.6.1.4 are affected. Other versions may also be affected.

Weakness

The product checks the state of a resource before using that resource, but the resource’s state can change between the check and the use in a way that invalidates the results of the check.

Affected Software

NameVendorStart VersionEnd Version
Server_intrusion_protectionBullwall4.6.0.0 (including)4.6.0.0 (including)
Server_intrusion_protectionBullwall4.6.0.6 (including)4.6.0.6 (including)
Server_intrusion_protectionBullwall4.6.0.7 (including)4.6.0.7 (including)
Server_intrusion_protectionBullwall4.6.1.4 (including)4.6.1.4 (including)

Potential Mitigations

References