Impact
An authenticated KSL client can send a start message that contains a checksum algorithm name. The boks_ksllogsd service copies the name into a fixed 16‑byte buffer without verifying its length. If the supplied name is longer than 16 bytes but is still a digest recognized by OpenSSL, the copy operation overruns the heap allocation. The overflow corrupts adjacent memory and can cause the daemon to crash or, if the overwritten memory contains executable code, enable arbitrary execution. This classic buffer overflow is identified as CWE‑787.
Affected Systems
The vulnerability exists in the boks-ksllogsd component of Fortra BoKS Manager. All releases before boks-server 8.1.0.24 on the 8.x maintenance line or before boks-server 9.0.0.7 on the 9.x line are affected.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. No EPSS score is available and the issue is not listed in the CISA KEV catalog, but the memory corruption can be triggered only by an authenticated attacker. Therefore an adversary must first obtain valid credentials or compromise a trusted client. Once authenticated, the attacker can craft a KSL start message with an oversized checksum name to trigger the overflow, potentially leading to process termination or code execution. The impact is limited to the boks_ksllogsd process but could extend to the overall BoKS Manager installation if elevated privileges are achieved.
OpenCVE Enrichment