MEDIUM🇬🇧 English

CVE-2025-62000

CVSS 6.9v4.0pub. 2025-12-18upd. 2026-01-14

BullWall Ransomware Containment może nie zawsze wykryć zaszyfrowany plik. Problem dotyczy specjalnej metody inspekji plików, która ocenia zawartość na podstawie bajtów nagłówka. Uwierzytelniony attakujący mógłby szyfrować pliki, zachowując pierwsze cztery bajty i uniemożliwiając uruchomienie tej metody. Produkt implementuje dodatkowe mechanizmy detekcji oparte na integralności, zdolne do identyfikacji uszkodzenia lub szyfrowania dla niektórych popularnych rozszerzeń plików niezależnie od bajtów nagłówka. W rezultacie podatność nie stanowi całkowitego obejścia ochrony przed ransomware, lecz ograniczenie jednej metody detekcji przy ocenie w izolacji. Dotykane są wersje 4.6.0.0, 4.6.0.6, 4.6.0.7 i 4.6.1.4. Inne wersje mogą również być dotknięte.

Pokaż oryginał (EN)

BullWall Ransomware Containment may not always detect an encrypted file. This issue affects a specific file inspection method that evaluates file content based on header bytes. An authenticated attacker could encrypt files, preserving the first four bytes and preventing this particular method from triggering. The affected product implements additional integrity-based detection mechanisms capable of identifying file corruption or encryption for some common file extensions independent of header bytes. As a result, this vulnerability does not represent a complete bypass of ransomware detection, but a limitation of one detection method when evaluated independently. Versions 4.6.0.0, 4.6.0.6, 4.6.0.7, and 4.6.1.4 are affected. Other versions may also be affected. BullWall plans to improve detection method documentation.

CVSS Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Bullwall Ransomware Containment

    APP
    Bullwall
    4.6.0.04.6.0.64.6.0.74.6.1.4
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2025-62001HIGH8.7ten sam produkt

BullWall Ransomware Containment supports configurable file and directory exclusions such as '$RECYCLE.BIN' to ...

CVE-2025-62002MEDIUM5.3ten sam produkt

BullWall Ransomware Containment określa liczbę zmodyfikowanych plików do wyzwolenia detekcji. Uwierzytelniony ...

CVE-2025-62003HIGH7.7ten sam vendor

BullWall Server Intrusion Protection has a noticeable configuration-dependent delay before the MFA check for R...

CVE-2025-62004HIGH7.7ten sam vendor

BullWall Server Intrusion Protection (SIP) services are initialized after login services during system startup...