Impact
Fortra BoKS Manager includes an insecure temporary file vulnerability in bccgethostcert that produces predictable temporary files without setting a restrictive umask, allowing a local user who can read files in the BOKS_tmp directory to capture CA secret or host private‑key material while the utility runs or to retrieve leftover secret material after successful certificate creation.
Affected Systems
The vulnerability affects the Fortra BoKS Manager product; specific version information was not provided in the advisory.
Risk and Exploitability
The CVSS score of 7.9 indicates a high severity data‑exposure risk, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. A local attacker with read access to the BoKS Master’s temporary directory can exploit the weakness; the risk remains contingent on local privilege and directory accessibility.
OpenCVE Enrichment