Записи Forescout
13 опубликованных записей вендора forescout.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 7,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-379 Creation of Temporary File in Directory with Insecure Permissions2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-20 Improper Input Validation1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-269 Improper Privilege Management1
- CWE-1188 Initialization of a Resource with an Insecure Default1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
13 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
34Наблюдать | CVE-2025-4660Proof of concept | Remote Code Execution in Windows Secure Connector/ HPS Inspection Engine via Insecure Named Pipe Accessforescout · secureconnector · CWE-276 | Высокая8,7 | — | 1,1 % | 13 мая 2025 г. |
34Наблюдать | CVE-2024-9950Proof of concept | Abuse of Unauthenticated Compliance Recheck in SecureConnectorforescout · secureconnector · CWE-379 | Высокая8,5 | — | 0,3 % | 2 янв. 2025 г. |
31Наблюдать | CVE-2016-9485Эксплойта нет | On Windows endpoints, the SecureConnector agent is vulnerable to privilege escalation whereby an authenticated unprivileged user can obtain administrator privilforescout · secureconnector · CWE-378 | Высокая7,8 | — | 1,3 % | 13 июл. 2018 г. |
31Наблюдать | CVE-2016-9486Эксплойта нет | On Windows endpoints, the SecureConnector agent is vulnerable to privilege escalation whereby an authenticated unprivileged user can obtain administrator privilforescout · secureconnector · CWE-379 | Высокая7,8 | — | 1,3 % | 13 июл. 2018 г. |
31Наблюдать | CVE-2021-28098Эксплойта нет | An issue was discovered in Forescout CounterACT before 8.1.4.forescout · counteract · CWE-59 | Высокая7,8 | — | 0,4 % | 14 апр. 2021 г. |
31Наблюдать | CVE-2023-39374Эксплойта нет | ForeScout NAC SecureConnector – CWE-427: Uncontrolled Search Path Elementforescout · secureconnector · CWE-427 | Высокая7,8 | — | 0,2 % | 3 сент. 2023 г. |
28Наблюдать | CVE-2024-22795Эксплойта нет | Insecure Permissions vulnerability in Forescout SecureConnector v.11.3.06.0063 allows a local attacker to escalate privileges via the Rechecforescout · secureconnector · CWE-269 | Высокая7,0 | — | 0,3 % | 8 февр. 2024 г. |
26Наблюдать | CVE-2012-4982Proof of concept | Open redirect vulnerability in assets/login on the Forescout CounterACT NAC device before 7.0 allows remote attackers to redirect users to aforescout · counteract · CWE-20 | Средняя5,8 | — | 8,9 % | 5 дек. 2012 г. |
23Наблюдать | CVE-2024-9949Эксплойта нет | Denial of Service in Forescout SecureConnectorforescout · secureconnector · CWE-1188 | Средняя5,8 | — | 0,1 % | 23 окт. 2024 г. |
22Наблюдать | CVE-2021-36724Эксплойта нет | ForeScout - SecureConnector Local Service DoSforescout · secureconnector · CWE-120 | Средняя5,5 | — | 0,2 % | 29 дек. 2021 г. |
18Наблюдать | CVE-2012-4985Эксплойта нет | The Forescout CounterACT NAC device 6.3.4.1 does not block ARP and ICMP traffic from unrecognized clients, which allows remote attackers to forescout · counteract · CWE-264 | Средняя4,3 | — | 1,7 % | 5 дек. 2012 г. |
17Наблюдать | CVE-2012-1825Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in the status program on the ForeScout CounterACT appliance with software 6.3.3.2 througforescout · counteract · CWE-79 | Средняя4,3 | — | 1,0 % | 11 июн. 2012 г. |
17Наблюдать | CVE-2012-4983Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities on the Forescout CounterACT NAC device before 7.0 allow remote attackers to inject arbitforescout · counteract · CWE-79 | Средняя4,3 | — | 0,9 % | 5 дек. 2012 г. |
- CVE-2025-466034Наблюдать
Remote Code Execution in Windows Secure Connector/ HPS Inspection Engine via Insecure Named Pipe Access
ВысокаяCVSS 8,7Proof of conceptEPSS 1 %forescout · secureconnector13 мая 2025 г.
- CVE-2024-995034Наблюдать
Abuse of Unauthenticated Compliance Recheck in SecureConnector
ВысокаяCVSS 8,5Proof of conceptEPSS 0 %forescout · secureconnector2 янв. 2025 г.
- CVE-2016-948531Наблюдать
On Windows endpoints, the SecureConnector agent is vulnerable to privilege escalation whereby an authenticated unprivileged user can obtain administrator privil
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %forescout · secureconnector13 июл. 2018 г.
- CVE-2016-948631Наблюдать
On Windows endpoints, the SecureConnector agent is vulnerable to privilege escalation whereby an authenticated unprivileged user can obtain administrator privil
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %forescout · secureconnector13 июл. 2018 г.
- CVE-2021-2809831Наблюдать
An issue was discovered in Forescout CounterACT before 8.1.4.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %forescout · counteract14 апр. 2021 г.
- CVE-2023-3937431Наблюдать
ForeScout NAC SecureConnector – CWE-427: Uncontrolled Search Path Element
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %forescout · secureconnector3 сент. 2023 г.
- CVE-2024-2279528Наблюдать
Insecure Permissions vulnerability in Forescout SecureConnector v.11.3.06.0063 allows a local attacker to escalate privileges via the Rechec
ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %forescout · secureconnector8 февр. 2024 г.
- CVE-2012-498226Наблюдать
Open redirect vulnerability in assets/login on the Forescout CounterACT NAC device before 7.0 allows remote attackers to redirect users to a
СредняяCVSS 5,8Proof of conceptEPSS 9 %forescout · counteract5 дек. 2012 г.
- CVE-2024-994923Наблюдать
Denial of Service in Forescout SecureConnector
СредняяCVSS 5,8Эксплойта нетEPSS 0 %forescout · secureconnector23 окт. 2024 г.
- CVE-2021-3672422Наблюдать
ForeScout - SecureConnector Local Service DoS
СредняяCVSS 5,5Эксплойта нетEPSS 0 %forescout · secureconnector29 дек. 2021 г.
- CVE-2012-498518Наблюдать
The Forescout CounterACT NAC device 6.3.4.1 does not block ARP and ICMP traffic from unrecognized clients, which allows remote attackers to
СредняяCVSS 4,3Эксплойта нетEPSS 2 %forescout · counteract5 дек. 2012 г.
- CVE-2012-182517Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in the status program on the ForeScout CounterACT appliance with software 6.3.3.2 throug
СредняяCVSS 4,3Эксплойта нетEPSS 1 %forescout · counteract11 июн. 2012 г.
- CVE-2012-498317Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities on the Forescout CounterACT NAC device before 7.0 allow remote attackers to inject arbit
СредняяCVSS 4,3Эксплойта нетEPSS 1 %forescout · counteract5 дек. 2012 г.