Insecure defaults in the Server Agent component of Fortra's Core Privileged Access Manager (BoKS) can result in the selection of weak password hash algorithms.  This issue affects BoKS Server Agent 9.0 instances that support yescrypt and are running in a BoKS 8.1 domain.
History

Tue, 16 Dec 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 16 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
Description Insecure defaults in the Server Agent component of Fortra's Core Privileged Access Manager (BoKS) can result in the selection of weak password hash algorithms.  This issue affects BoKS Server Agent 9.0 instances that support yescrypt and are running in a BoKS 8.1 domain.
Title Weak Password Hash in Core Privileged Access Manager (BoKS)
Weaknesses CWE-916
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Fortra

Published: 2025-12-16T20:01:02.743Z

Updated: 2025-12-16T20:23:51.768Z

Reserved: 2025-11-21T21:04:44.245Z

Link: CVE-2025-13532

cve-icon Vulnrichment

Updated: 2025-12-16T20:18:54.152Z

cve-icon NVD

Status : Received

Published: 2025-12-16T20:15:47.467

Modified: 2025-12-16T20:15:47.467

Link: CVE-2025-13532

cve-icon Redhat

No data.