Fortra BoKS Manager 中的 工具存在不安全的临时文件漏洞。该工具在创建可预测的临时文件之前,未先设置严格的 (用户掩码)。BoKS Master 上的本地用户若能读取位于 目录下的文件,则可能在工具运行期间获取 CA 私钥或主机私钥材料,或在证书成功创建后获取遗留的 CA 密钥材料。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Fortra | BoKS Manager | 8.1.0.0 ~ 8.1.0.23 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-79901 | 9.9 CRITICAL | Predictable Active Directory service-account passwords in BoKS Manager |
| CVE-2026-79898 | 9.1 CRITICAL | Fortra BoKS Manager crlserver command injection vulnerability |
| CVE-2026-79900 | 6.5 MEDIUM | Heap overflow in KSL checksum initialization |
No comments yet