CVE-2025-13532: Weak Password Hash in Core Privileged Access Manager (BoKS)
Insecure defaults in the Server Agent component of Fortra's Core Privileged Access Manager (BoKS) can result in the selection of weak password hash algorithms. This issue affects BoKS Server Agent 9.0 instances that support yescrypt and are running in a BoKS 8.1 domain.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13532?
CVE-2025-13532 is considered a high severity vulnerability due to the potential for weak password hashes.
How do I fix CVE-2025-13532?
To mitigate CVE-2025-13532, ensure that your BoKS Server Agent 9.0 is configured to use stronger password hash algorithms instead of the insecure defaults.
What versions are affected by CVE-2025-13532?
CVE-2025-13532 affects BoKS Server Agent 9.0 when it is running in a BoKS 8.1 domain.
What are the risks associated with CVE-2025-13532?
The risks associated with CVE-2025-13532 include the possibility of unauthorized access due to weak password hash algorithms.
Is there a patch available for CVE-2025-13532?
Currently, no specific patch is mentioned for CVE-2025-13532; users should review and adjust their configurations to ensure secure practices.