Fortra Boks Manager Boks-Server vulnerabilities
2 known vulnerabilities affecting fortra/boks_manager_boks-server.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2026-79901P2CRITICALCVSS 9.9fixed in 9.0.0.62026-10-01
CVE-2026-79901 [CRITICAL] CWE-338 CVE-2026-79901: In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Dire
In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify
nvd
CVE-2026-79900P3MEDIUMCVSS 6.5fixed in 8.1.0.24fixed in 9.0.0.72026-10-01
CVE-2026-79900 [MEDIUM] CWE-787 CVE-2026-79900: boks_ksllogsd accepts a checksum algorithm name in the MD field of an authenticated KSL start messag
boks_ksllogsd accepts a checksum algorithm name in the MD field of an authenticated KSL start message. Affected releases verify that OpenSSL recognizes the digest name but do not verify that the value fits in a fixed 16-byte checksum context field before copying it. An authenticated KSL client can supply an oversized, OpenSSL-recognized digest name
nvd