CVE-2018-20764: Helpsystems Boks

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

A buffer overflow exists in HelpSystems tcpcrypt on Linux, used for BoKS encrypted telnet through BoKS version 6.7.1. Since tcpcrypt is setuid, exploitation leads to privilege escalation.

Affected products

  • Helpsystems Boks: from 6.6.0, up to and including 6.7.1

Published 2019-02-08. Last modified 2026-06-17.