{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2025-13532",
        "assignerOrgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
        "state": "PUBLISHED",
        "assignerShortName": "Fortra",
        "dateReserved": "2025-11-21T21:04:44.245Z",
        "datePublished": "2025-12-16T20:01:02.743Z",
        "dateUpdated": "2025-12-16T20:23:51.768Z"
    },
    "containers": {
        "cna": {
            "affected": [
                {
                    "defaultStatus": "unaffected",
                    "platforms": [
                        "Linux"
                    ],
                    "product": "Core Privileged Access Manager (BoKS)",
                    "vendor": "Fortra",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "This issue affects BoKS Server Agent 9.0 instances that support yescrypt and are running in a BoKS 8.1 domain. The affected platforms are: Debian 11, 12, 13, RedHat 9, 10 and Ubuntu 24."
                        }
                    ]
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "Insecure defaults in the Server Agent component of Fortra's Core Privileged Access Manager (BoKS) can result in the selection of weak password hash algorithms. &nbsp;<span style=\"background-color: rgb(255, 255, 255);\">This issue a</span><span style=\"background-color: rgb(255, 255, 255);\">ffects BoKS Server Agent 9.0 instances that support yescrypt and are running in a BoKS 8.1 domain.</span>"
                        }
                    ],
                    "value": "Insecure defaults in the Server Agent component of Fortra's Core Privileged Access Manager (BoKS) can result in the selection of weak password hash algorithms.  This issue affects BoKS Server Agent 9.0 instances that support yescrypt and are running in a BoKS 8.1 domain."
                }
            ],
            "impacts": [
                {
                    "capecId": "CAPEC-112",
                    "descriptions": [
                        {
                            "lang": "en",
                            "value": "CAPEC-112 Brute Force"
                        }
                    ]
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "attackComplexity": "LOW",
                        "attackVector": "LOCAL",
                        "availabilityImpact": "NONE",
                        "baseScore": 6.2,
                        "baseSeverity": "MEDIUM",
                        "confidentialityImpact": "HIGH",
                        "integrityImpact": "NONE",
                        "privilegesRequired": "NONE",
                        "scope": "UNCHANGED",
                        "userInteraction": "NONE",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ]
                }
            ],
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "cweId": "CWE-916",
                            "description": "CWE-916 Use of Password Hash With Insufficient Computational Effort",
                            "lang": "en",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "providerMetadata": {
                "orgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
                "shortName": "Fortra",
                "dateUpdated": "2025-12-16T20:01:02.743Z"
            },
            "references": [
                {
                    "url": "https://www.fortra.com/security/advisories/product-security/fi-2025-014"
                }
            ],
            "solutions": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "Upgrade to BoKS Server Agent 9.0.0.4.\n\n<br>"
                        }
                    ],
                    "value": "Upgrade to BoKS Server Agent 9.0.0.4."
                }
            ],
            "source": {
                "discovery": "UNKNOWN"
            },
            "title": "Weak Password Hash in Core Privileged Access Manager (BoKS)",
            "workarounds": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "Configure the OS to use SHA512 rather than yescrypt.\n\n<br>"
                        }
                    ],
                    "value": "Configure the OS to use SHA512 rather than yescrypt."
                }
            ],
            "x_generator": {
                "engine": "Vulnogram 0.5.0"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2025-12-16T20:18:38.616690Z",
                                "id": "CVE-2025-13532",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2025-12-16T20:23:51.768Z"
                }
            }
        ]
    }
}