Full Report
Fortra security advisory (AV26-987)
Analysis Summary
# Vulnerability: Multiple Buffer Overflows in Fortra BoKS Manager
## CVE Details
*Note: The provided source lists advisory IDs FI-2026-013 and FI-2026-017; specific CVE identifiers were not explicitly detailed in the summary text.*
- **CVE ID**: Pending/See Advisory FI-2026-013 & FI-2026-017
- **CVSS Score**: Not explicitly stated (Likely High/Critical based on "Buffer Overflow" classification)
- **CWE**: CWE-122 (Heap-based Buffer Overflow), CWE-121 (Stack-based Buffer Overflow)
## Affected Systems
- **Products**: Fortra Core Privileged Access Manager (BoKS) - BoKS Manager (`boks-server`)
- **Versions**:
- Versions prior to 8.1.0.24
- Versions prior to 9.0.0.7
- **Configurations**: Systems utilizing KSL (Kea Security Layer) checksum initialization or the autoregistration feature.
## Vulnerability Description
This advisory covers two distinct memory corruption vulnerabilities within the `boks-server` component:
1. **Heap Overflow in KSL Checksum Initialization**: A flaw exists during the initialization of the Kea Security Layer checksums where an improperly validated input can lead to a heap-based buffer overflow.
2. **Autoregistration Stack Buffer Overflow**: A vulnerability in the BoKS autoregistration process where insufficient bounds checking on supplied data allows for a stack-based buffer overflow.
## Exploitation
- **Status**: Not specified (Typically, these flaws are discovered by internal research or reported via bug bounties; no mention of active exploitation in the wild was provided).
- **Complexity**: Likely Medium (Requires specific knowledge of BoKS communication protocols).
- **Attack Vector**: Network (Both features generally interact with remote clients/agents).
## Impact
- **Confidentiality**: High (Potential for memory leakage or unauthorized data access).
- **Integrity**: High (Potential for unauthorized modification of security policies or system state).
- **Availability**: High (Potential for service crashes or remote code execution).
## Remediation
### Patches
Fortra has released the following versions to address these vulnerabilities:
- **BoKS Manager 8.1.0.24** or later
- **BoKS Manager 9.0.0.7** or later
### Workarounds
- No specific workarounds were provided in the advisory summary. It is recommended to restrict network access to the BoKS Manager server to trusted administrative segments until patches are applied.
## Detection
- **Indicators of Compromise**: Monitor for unexpected crashes of the `boks-server` service or unusual KSL-related error logs.
- **Detection methods and tools**: Utilize vulnerability scanners to identify outdated versions of the `boks-server` package. Review system logs for segmentation faults associated with the autoregistration process.
## References
- Fortra Security Advisory FI-2026-013: hxxps[://]www[.]fortra[.]com/security/advisories/product-security/fi-2026-013
- Fortra Security Advisory FI-2026-017: hxxps[://]www[.]fortra[.]com/security/advisories/product-security/fi-2026-017
- Cyber Centre Advisory (AV26-987): hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/fortra-security-advisory-av26-987