CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 7.5. Exploitation may require the attacker to be authenticated.
CVE
CVE-2025-62004
Severity
HIGH
CVSS
7.5
EPSS
0.29%
Original NVD Description
BullWall Server Intrusion Protection (SIP) services are initialized after login services during system startup. A local, authenticated attacker can log in after boot and before SIP MFA is running. The SIP services do not retroactively enforce MFA or disconnect sessions that were not subject to SIP MFA. Versions 4.6.0.0, 4.6.0.6, 4.6.0.7, and 4.6.1.4 are affected. Other versions mayy also be affected. BullWall plans to improve detection method documentation.
Related CVEs
Other vulnerabilities affecting the same vendor(s)