Impact
In affected BoKS deployments the keytab manager generates Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. Because the sequence is deterministic, an attacker who knows the service principal and can estimate the password-change time can reconstruct a limited set of candidate passwords and verify them offline, allowing credential compromise of service accounts and undermining Kerberos authentication.
Affected Systems
This flaw affects BoKS Manager installations provided by Fortra (boks-server) that use the BoKS keytab management module. Versions prior to boks-server 9.0.0.7 are vulnerable; the identified solution upgrades to that version. No other products or versions are listed.
Risk and Exploitability
The CVSS score of 9.9 indicates critical severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires only knowledge of the service principal and an estimation of the password-change timestamp, after which the attacker can compute the candidate passwords offline. The impact is the potential compromise of service-account credentials and denial of Kerberos authentication for affected principals.
OpenCVE Enrichment