CyberRota Analysis
AI-GeneratedFortra BoKS Manager is vulnerable due to an out-of-bounds read in the TLS ClientHello parser utilized by boks_portmux, allowing remote unauthenticated attackers to exploit this flaw. By sending malformed ClientHello messages, an attacker can disrupt the service, leading to potential denial-of-service conditions despite automatic restarts. Organizations using Fortra BoKS Manager should prioritize patching this vulnerability to mitigate the risk of service interruptions.
Original NVD Description
Fortra BoKS Manager contains an out-of-bounds read vulnerability in the custom TLS ClientHello parser used by boks_portmux. A remote unauthenticated attacker can submit a malformed ClientHello and terminate boks_portmux. Although the daemon is normally restarted automatically, repeated requests can sustain the service interruption.