Impact
Fortra BoKS Manager has a command injection flaw in crlserver, enabling an authenticated user who can add CRL URLs to run arbitrary shell commands as root on the master server. This vulnerability can lead to full system compromise, data loss, and service disruption, representing a critical security risk and covering CWE-78.
Affected Systems
The flaw affects Fortra BoKS Manager installations of the boks-server product line. Any version of boks-server earlier than 8.1.0.24 in the 8.x series or earlier than 9.0.0.7 in the 9.x series is impacted, especially when using the BCC tool, WSI REST/SOAP APIs, or the cacrl command‑line interface to add CRL URLs.
Risk and Exploitability
The CVSS score of 9.1 indicates a critical severity. Because the EPSS score is unavailable, the precise exploit probability is uncertain, yet the presence of network‑accessible administrative paths via BCC and WSI makes exploitation plausible. The flaw is not listed in the CISA KEV catalog. An attacker who authenticates to add a CRL URL—whether through a web‑service interface or the cacrl tool—can inject shell commands that execute with root privileges on the BoKS Master.
OpenCVE Enrichment