Insecure defaults in the Server Agent component of Fortra's Core Privileged Access Manager (BoKS) can result in the selection of weak password hash algorithms.  This issue affects BoKS Server Agent 9.0 instances that support yescrypt and are running in a BoKS 8.1 domain.
Advisories

No advisories yet.

Fixes

Solution

Upgrade to BoKS Server Agent 9.0.0.4.


Workaround

Configure the OS to use SHA512 rather than yescrypt.

History

Tue, 16 Dec 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 16 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
Description Insecure defaults in the Server Agent component of Fortra's Core Privileged Access Manager (BoKS) can result in the selection of weak password hash algorithms.  This issue affects BoKS Server Agent 9.0 instances that support yescrypt and are running in a BoKS 8.1 domain.
Title Weak Password Hash in Core Privileged Access Manager (BoKS)
Weaknesses CWE-916
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Fortra

Published:

Updated: 2025-12-16T20:23:51.768Z

Reserved: 2025-11-21T21:04:44.245Z

Link: CVE-2025-13532

cve-icon Vulnrichment

Updated: 2025-12-16T20:18:54.152Z

cve-icon NVD

Status : Received

Published: 2025-12-16T20:15:47.467

Modified: 2025-12-16T20:15:47.467

Link: CVE-2025-13532

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses