BullWall Ransomware Containment supports configurable file and directory exclusions such as '$RECYCLE.BIN' to balance monitoring scope and performance. Certain exclusion patterns could allow an authenticated attacker to rename directories in a way that avoids monitoring. Fixed in 4.6.1.14 and 5.0.0.42, which remove hardcoded exclusion behavior and exposes exclusion handling as configurable settings.
oryginał ENCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XBullwall Ransomware Containment
APPBullwall4.6.0.04.6.0.64.6.0.74.6.1.4
Powiązane podatności
BullWall Ransomware Containment może nie zawsze wykryć zaszyfrowany plik. Problem dotyczy specjalnej metody in...
BullWall Ransomware Containment określa liczbę zmodyfikowanych plików do wyzwolenia detekcji. Uwierzytelniony ...
BullWall Server Intrusion Protection has a noticeable configuration-dependent delay before the MFA check for R...
BullWall Server Intrusion Protection (SIP) services are initialized after login services during system startup...