Forescout records
13 published records for vendor forescout.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 7.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-379 Creation of Temporary File in Directory with Insecure Permissions2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-20 Improper Input Validation1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-269 Improper Privilege Management1
- CWE-1188 Initialization of a Resource with an Insecure Default1
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
13 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
34Monitor | CVE-2025-4660Proof of concept | Remote Code Execution in Windows Secure Connector/ HPS Inspection Engine via Insecure Named Pipe Accessforescout · secureconnector · CWE-276 | High8.7 | — | 1.1% | May 13, 2025 |
34Monitor | CVE-2024-9950Proof of concept | Abuse of Unauthenticated Compliance Recheck in SecureConnectorforescout · secureconnector · CWE-379 | High8.5 | — | 0.3% | Jan 2, 2025 |
31Monitor | CVE-2016-9485No exploit | On Windows endpoints, the SecureConnector agent is vulnerable to privilege escalation whereby an authenticated unprivileged user can obtain administrator privilforescout · secureconnector · CWE-378 | High7.8 | — | 1.3% | Jul 13, 2018 |
31Monitor | CVE-2016-9486No exploit | On Windows endpoints, the SecureConnector agent is vulnerable to privilege escalation whereby an authenticated unprivileged user can obtain administrator privilforescout · secureconnector · CWE-379 | High7.8 | — | 1.3% | Jul 13, 2018 |
31Monitor | CVE-2021-28098No exploit | An issue was discovered in Forescout CounterACT before 8.1.4.forescout · counteract · CWE-59 | High7.8 | — | 0.4% | Apr 14, 2021 |
31Monitor | CVE-2023-39374No exploit | ForeScout NAC SecureConnector – CWE-427: Uncontrolled Search Path Elementforescout · secureconnector · CWE-427 | High7.8 | — | 0.2% | Sep 3, 2023 |
28Monitor | CVE-2024-22795No exploit | Insecure Permissions vulnerability in Forescout SecureConnector v.11.3.06.0063 allows a local attacker to escalate privileges via the Rechecforescout · secureconnector · CWE-269 | High7.0 | — | 0.3% | Feb 8, 2024 |
26Monitor | CVE-2012-4982Proof of concept | Open redirect vulnerability in assets/login on the Forescout CounterACT NAC device before 7.0 allows remote attackers to redirect users to aforescout · counteract · CWE-20 | Medium5.8 | — | 8.9% | Dec 5, 2012 |
23Monitor | CVE-2024-9949No exploit | Denial of Service in Forescout SecureConnectorforescout · secureconnector · CWE-1188 | Medium5.8 | — | 0.1% | Oct 23, 2024 |
22Monitor | CVE-2021-36724No exploit | ForeScout - SecureConnector Local Service DoSforescout · secureconnector · CWE-120 | Medium5.5 | — | 0.2% | Dec 29, 2021 |
18Monitor | CVE-2012-4985No exploit | The Forescout CounterACT NAC device 6.3.4.1 does not block ARP and ICMP traffic from unrecognized clients, which allows remote attackers to forescout · counteract · CWE-264 | Medium4.3 | — | 1.7% | Dec 5, 2012 |
17Monitor | CVE-2012-1825No exploit | Multiple cross-site scripting (XSS) vulnerabilities in the status program on the ForeScout CounterACT appliance with software 6.3.3.2 througforescout · counteract · CWE-79 | Medium4.3 | — | 1.0% | Jun 11, 2012 |
17Monitor | CVE-2012-4983No exploit | Multiple cross-site scripting (XSS) vulnerabilities on the Forescout CounterACT NAC device before 7.0 allow remote attackers to inject arbitforescout · counteract · CWE-79 | Medium4.3 | — | 0.9% | Dec 5, 2012 |
- CVE-2025-466034Monitor
Remote Code Execution in Windows Secure Connector/ HPS Inspection Engine via Insecure Named Pipe Access
HighCVSS 8.7Proof of conceptEPSS 1%forescout · secureconnectorMay 13, 2025
- CVE-2024-995034Monitor
Abuse of Unauthenticated Compliance Recheck in SecureConnector
HighCVSS 8.5Proof of conceptEPSS 0%forescout · secureconnectorJan 2, 2025
- CVE-2016-948531Monitor
On Windows endpoints, the SecureConnector agent is vulnerable to privilege escalation whereby an authenticated unprivileged user can obtain administrator privil
HighCVSS 7.8No exploitEPSS 1%forescout · secureconnectorJul 13, 2018
- CVE-2016-948631Monitor
On Windows endpoints, the SecureConnector agent is vulnerable to privilege escalation whereby an authenticated unprivileged user can obtain administrator privil
HighCVSS 7.8No exploitEPSS 1%forescout · secureconnectorJul 13, 2018
- CVE-2021-2809831Monitor
An issue was discovered in Forescout CounterACT before 8.1.4.
HighCVSS 7.8No exploitEPSS 0%forescout · counteractApr 14, 2021
- CVE-2023-3937431Monitor
ForeScout NAC SecureConnector – CWE-427: Uncontrolled Search Path Element
HighCVSS 7.8No exploitEPSS 0%forescout · secureconnectorSep 3, 2023
- CVE-2024-2279528Monitor
Insecure Permissions vulnerability in Forescout SecureConnector v.11.3.06.0063 allows a local attacker to escalate privileges via the Rechec
HighCVSS 7.0No exploitEPSS 0%forescout · secureconnectorFeb 8, 2024
- CVE-2012-498226Monitor
Open redirect vulnerability in assets/login on the Forescout CounterACT NAC device before 7.0 allows remote attackers to redirect users to a
MediumCVSS 5.8Proof of conceptEPSS 9%forescout · counteractDec 5, 2012
- CVE-2024-994923Monitor
Denial of Service in Forescout SecureConnector
MediumCVSS 5.8No exploitEPSS 0%forescout · secureconnectorOct 23, 2024
- CVE-2021-3672422Monitor
ForeScout - SecureConnector Local Service DoS
MediumCVSS 5.5No exploitEPSS 0%forescout · secureconnectorDec 29, 2021
- CVE-2012-498518Monitor
The Forescout CounterACT NAC device 6.3.4.1 does not block ARP and ICMP traffic from unrecognized clients, which allows remote attackers to
MediumCVSS 4.3No exploitEPSS 2%forescout · counteractDec 5, 2012
- CVE-2012-182517Monitor
Multiple cross-site scripting (XSS) vulnerabilities in the status program on the ForeScout CounterACT appliance with software 6.3.3.2 throug
MediumCVSS 4.3No exploitEPSS 1%forescout · counteractJun 11, 2012
- CVE-2012-498317Monitor
Multiple cross-site scripting (XSS) vulnerabilities on the Forescout CounterACT NAC device before 7.0 allow remote attackers to inject arbit
MediumCVSS 4.3No exploitEPSS 1%forescout · counteractDec 5, 2012