CVE Feed

    Dashboard / CVE / CVE-2025-62004

    CVE-2025-62004

    BullWall Server Intrusion Protection (SIP) services are initialized after login services during system startup. A local, authenticated attacker can log in after boot and before SIP MFA is running. The SIP services do not retroactively enforce MFA or disconnect sessions that were not subject to SIP MFA. Versions 4.6.0.0, 4.6.0.6, 4.6.0.7, and 4.6.1.4 are affected. Other versions mayy also be affected. BullWall plans to improve detection method documentation.

    Published:Dec 18, 2025
    Last Modified:Jan 15, 2026
    EPS:Dec 18, 2025
    EPSS Score:0.00038
    CVSS Score:7.5

    Affected Products

    Vendor
    Bullwall
    Product
    Server Intrusion Protection

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High