BullWall Ransomware Containment może nie zawsze wykryć zaszyfrowany plik. Problem dotyczy specjalnej metody inspekji plików, która ocenia zawartość na podstawie bajtów nagłówka. Uwierzytelniony attakujący mógłby szyfrować pliki, zachowując pierwsze cztery bajty i uniemożliwiając uruchomienie tej metody. Produkt implementuje dodatkowe mechanizmy detekcji oparte na integralności, zdolne do identyfikacji uszkodzenia lub szyfrowania dla niektórych popularnych rozszerzeń plików niezależnie od bajtów nagłówka. W rezultacie podatność nie stanowi całkowitego obejścia ochrony przed ransomware, lecz ograniczenie jednej metody detekcji przy ocenie w izolacji. Dotykane są wersje 4.6.0.0, 4.6.0.6, 4.6.0.7 i 4.6.1.4. Inne wersje mogą również być dotknięte.
▸ Pokaż oryginał (EN)
BullWall Ransomware Containment may not always detect an encrypted file. This issue affects a specific file inspection method that evaluates file content based on header bytes. An authenticated attacker could encrypt files, preserving the first four bytes and preventing this particular method from triggering. The affected product implements additional integrity-based detection mechanisms capable of identifying file corruption or encryption for some common file extensions independent of header bytes. As a result, this vulnerability does not represent a complete bypass of ransomware detection, but a limitation of one detection method when evaluated independently. Versions 4.6.0.0, 4.6.0.6, 4.6.0.7, and 4.6.1.4 are affected. Other versions may also be affected. BullWall plans to improve detection method documentation.
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XBullwall Ransomware Containment
APPBullwall4.6.0.04.6.0.64.6.0.74.6.1.4
Powiązane podatności
BullWall Ransomware Containment supports configurable file and directory exclusions such as '$RECYCLE.BIN' to ...
BullWall Ransomware Containment określa liczbę zmodyfikowanych plików do wyzwolenia detekcji. Uwierzytelniony ...
BullWall Server Intrusion Protection has a noticeable configuration-dependent delay before the MFA check for R...
BullWall Server Intrusion Protection (SIP) services are initialized after login services during system startup...