Fortra 的核心特权访问管理器(BoKS)在 组件中存在一个基于栈的缓冲区溢出漏洞。能够访问自动注册服务的远程攻击者可能在处理客户端响应时触发内存损坏。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Fortra | Fortra's Core Privileged Access Manager (BoKS) | 8.1.0.0≤ 8.1.0.23 |
affected |
9.0.0.0≤ 9.0.0.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Fortra | Fortra's Core Privileged Access Manager (BoKS) | 8.1.0.0 ~ 8.1.0.23 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-79901 | 9.9 CRITICAL | Predictable Active Directory service-account passwords in BoKS Manager |
| CVE-2026-79898 | 9.1 CRITICAL | Fortra BoKS Manager crlserver command injection vulnerability |
| CVE-2026-14316 | 8.1 HIGH | Heap buffer overflow in boks_sshd revoked-key error handling |
| CVE-2026-79899 | 7.9 HIGH | Fortra BoKS Manager bccgethostcert insecure temporary file vulnerability |
| CVE-2026-79896 | 7.5 HIGH | Fortra BoKS Manager boks_portmux TLS ClientHello out-of-bounds read vulnerability |
| CVE-2026-79900 | 6.5 MEDIUM | Heap overflow in KSL checksum initialization |
| CVE-2026-9864 | 4.8 MEDIUM | Fortra BoKS Server Agent adjoin machine-account password generation vulnerability |
No comments yet