Home

Description

Insecure defaults in the Server Agent component of Fortra's Core Privileged Access Manager (BoKS) can result in the selection of weak password hash algorithms.  This issue affects BoKS Server Agent 9.0 instances that support yescrypt and are running in a BoKS 8.1 domain.

PUBLISHED Reserved 2025-11-21 | Published 2025-12-16 | Updated 2025-12-16 | Assigner Fortra




MEDIUM: 6.2CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Problem types

CWE-916 Use of Password Hash With Insufficient Computational Effort

Product status

Default status
unaffected

This issue affects BoKS Server Agent 9.0 instances that support yescrypt and are running in a BoKS 8.1 domain. The affected platforms are: Debian 11, 12, 13, RedHat 9, 10 and Ubuntu 24.
affected

References

www.fortra.com/...ty/advisories/product-security/fi-2025-014

cve.org (CVE-2025-13532)

nvd.nist.gov (CVE-2025-13532)

Download JSON

Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.