forescout
Security Productscommercial
Top products
Latest CVEs
The 13 most recently published vulnerabilities affecting forescout.
- CVE-2025-4660Remote Code Execution in Windows Secure Connector/ HPS Inspection Engine via Insecure Named Pipe Access9.8
- CVE-2024-9950Abuse of Unauthenticated Compliance Recheck in SecureConnector7.8
- CVE-2024-9949Denial of Service in Forescout SecureConnector6.1
- CVE-2024-22795Insecure Permissions vulnerability in Forescout SecureConnector v.11.3.06.0063 allows a local attacker to escalate privileges via the Recheck Compliance Status component.7.0
- CVE-2023-39374 ForeScout NAC SecureConnector – CWE-427: Uncontrolled Search Path Element7.8
- CVE-2021-36724ForeScout - SecureConnector Local Service DoS6.1
- CVE-2021-28098An issue was discovered in Forescout CounterACT before 8.1.4. A local privilege escalation vulnerability is present in the logging function. SecureConnector runs with administrative privileges and ...7.8
- CVE-2016-9485On Windows endpoints, the SecureConnector agent is vulnerable to privilege escalation whereby an authenticated unprivileged user can obtain administrator privileges on the endpoint because it fails to set any permissions on downloaded file objects7.8
- CVE-2016-9486On Windows endpoints, the SecureConnector agent is vulnerable to privilege escalation whereby an authenticated unprivileged user can obtain administrator privileges on the endpoint because files are created in a folder with incorrect privileges7.8
- CVE-2012-4985The Forescout CounterACT NAC device 6.3.4.1 does not block ARP and ICMP traffic from unrecognized clients, which allows remote attackers to conduct ARP poisoning attacks via crafted packets.4.3
- CVE-2012-4983Multiple cross-site scripting (XSS) vulnerabilities on the Forescout CounterACT NAC device before 7.0 allow remote attackers to inject arbitrary web script or HTML via (1) the a parameter to assets...4.3
- CVE-2012-4982Open redirect vulnerability in assets/login on the Forescout CounterACT NAC device before 7.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL...5.8
- CVE-2012-1825Multiple cross-site scripting (XSS) vulnerabilities in the status program on the ForeScout CounterACT appliance with software 6.3.3.2 through 6.3.4.10 allow remote attackers to inject arbitrary web...4.3