Overview
- Fortra
- BoKS Manager boks-server
01 Oct 2026
Published
01 Oct 2026
Updated
CVSS v3.1
CRITICAL (9.9)
EPSS
0.27%
KEV
Description
In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline.
Statistics
- 1 Post
Last activity: 1 hour ago
Overview
- Fortra
- Fortra's Core Privileged Access Manager (BoKS)
01 Oct 2026
Published
01 Oct 2026
Updated
CVSS v3.1
CRITICAL (9.8)
EPSS
0.44%
KEV
Description
Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boks_autoregisterd. A remote attacker with network access to the autoregistration service may be able to trigger memory corruption during client response processing.
Statistics
- 1 Post
Last activity: 1 hour ago
Overview
- Fortra
- BoKS Manager
01 Oct 2026
Published
01 Oct 2026
Updated
CVSS v3.1
CRITICAL (9.1)
EPSS
0.98%
KEV
Description
Fortra BoKS Manager contains a command injection vulnerability in crlserver. An authenticated user authorized to add CRL URLs through BCC, the WSI REST or SOAP API, or the cacrl command-line interface could cause shell command substitution to be processed by crlserver as root on the BoKS Master. BCC and WSI provide network-accessible administration paths and do not require a local sudo or suexec rule; non-root use of cacrl requires such a rule.
Statistics
- 1 Post
Last activity: 1 hour ago