Description
Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration processing.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected products
- Fortra / Core Privileged Access Manager (BoKS)boks-server 8.1.0.0 – boks-server 8.1.0.22
- Fortra / Core Privileged Access Manager (BoKS)boks-server 9.0.0.0 – boks-server 9.0.0.4