Forescout kayıtları
forescout üreticisine ait 13 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %7,7
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-379 Creation of Temporary File in Directory with Insecure Permissions2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-20 Improper Input Validation1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-269 Improper Privilege Management1
- CWE-1188 Initialization of a Resource with an Insecure Default1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
13 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
34İzleyin | CVE-2025-4660Kavram kanıtı | Remote Code Execution in Windows Secure Connector/ HPS Inspection Engine via Insecure Named Pipe Accessforescout · secureconnector · CWE-276 | Yüksek8,7 | — | %1,1 | 13 May 2025 |
34İzleyin | CVE-2024-9950Kavram kanıtı | Abuse of Unauthenticated Compliance Recheck in SecureConnectorforescout · secureconnector · CWE-379 | Yüksek8,5 | — | %0,3 | 2 Oca 2025 |
31İzleyin | CVE-2016-9485İstismar yok | On Windows endpoints, the SecureConnector agent is vulnerable to privilege escalation whereby an authenticated unprivileged user can obtain administrator privilforescout · secureconnector · CWE-378 | Yüksek7,8 | — | %1,3 | 13 Tem 2018 |
31İzleyin | CVE-2016-9486İstismar yok | On Windows endpoints, the SecureConnector agent is vulnerable to privilege escalation whereby an authenticated unprivileged user can obtain administrator privilforescout · secureconnector · CWE-379 | Yüksek7,8 | — | %1,3 | 13 Tem 2018 |
31İzleyin | CVE-2021-28098İstismar yok | An issue was discovered in Forescout CounterACT before 8.1.4.forescout · counteract · CWE-59 | Yüksek7,8 | — | %0,4 | 14 Nis 2021 |
31İzleyin | CVE-2023-39374İstismar yok | ForeScout NAC SecureConnector – CWE-427: Uncontrolled Search Path Elementforescout · secureconnector · CWE-427 | Yüksek7,8 | — | %0,2 | 3 Eyl 2023 |
28İzleyin | CVE-2024-22795İstismar yok | Insecure Permissions vulnerability in Forescout SecureConnector v.11.3.06.0063 allows a local attacker to escalate privileges via the Rechecforescout · secureconnector · CWE-269 | Yüksek7,0 | — | %0,3 | 8 Şub 2024 |
26İzleyin | CVE-2012-4982Kavram kanıtı | Open redirect vulnerability in assets/login on the Forescout CounterACT NAC device before 7.0 allows remote attackers to redirect users to aforescout · counteract · CWE-20 | Orta5,8 | — | %8,9 | 5 Ara 2012 |
23İzleyin | CVE-2024-9949İstismar yok | Denial of Service in Forescout SecureConnectorforescout · secureconnector · CWE-1188 | Orta5,8 | — | %0,1 | 23 Eki 2024 |
22İzleyin | CVE-2021-36724İstismar yok | ForeScout - SecureConnector Local Service DoSforescout · secureconnector · CWE-120 | Orta5,5 | — | %0,2 | 29 Ara 2021 |
18İzleyin | CVE-2012-4985İstismar yok | The Forescout CounterACT NAC device 6.3.4.1 does not block ARP and ICMP traffic from unrecognized clients, which allows remote attackers to forescout · counteract · CWE-264 | Orta4,3 | — | %1,7 | 5 Ara 2012 |
17İzleyin | CVE-2012-1825İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in the status program on the ForeScout CounterACT appliance with software 6.3.3.2 througforescout · counteract · CWE-79 | Orta4,3 | — | %1,0 | 11 Haz 2012 |
17İzleyin | CVE-2012-4983İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities on the Forescout CounterACT NAC device before 7.0 allow remote attackers to inject arbitforescout · counteract · CWE-79 | Orta4,3 | — | %0,9 | 5 Ara 2012 |
- CVE-2025-466034İzleyin
Remote Code Execution in Windows Secure Connector/ HPS Inspection Engine via Insecure Named Pipe Access
YüksekCVSS 8,7Kavram kanıtıEPSS %1forescout · secureconnector13 May 2025
- CVE-2024-995034İzleyin
Abuse of Unauthenticated Compliance Recheck in SecureConnector
YüksekCVSS 8,5Kavram kanıtıEPSS %0forescout · secureconnector2 Oca 2025
- CVE-2016-948531İzleyin
On Windows endpoints, the SecureConnector agent is vulnerable to privilege escalation whereby an authenticated unprivileged user can obtain administrator privil
YüksekCVSS 7,8İstismar yokEPSS %1forescout · secureconnector13 Tem 2018
- CVE-2016-948631İzleyin
On Windows endpoints, the SecureConnector agent is vulnerable to privilege escalation whereby an authenticated unprivileged user can obtain administrator privil
YüksekCVSS 7,8İstismar yokEPSS %1forescout · secureconnector13 Tem 2018
- CVE-2021-2809831İzleyin
An issue was discovered in Forescout CounterACT before 8.1.4.
YüksekCVSS 7,8İstismar yokEPSS %0forescout · counteract14 Nis 2021
- CVE-2023-3937431İzleyin
ForeScout NAC SecureConnector – CWE-427: Uncontrolled Search Path Element
YüksekCVSS 7,8İstismar yokEPSS %0forescout · secureconnector3 Eyl 2023
- CVE-2024-2279528İzleyin
Insecure Permissions vulnerability in Forescout SecureConnector v.11.3.06.0063 allows a local attacker to escalate privileges via the Rechec
YüksekCVSS 7,0İstismar yokEPSS %0forescout · secureconnector8 Şub 2024
- CVE-2012-498226İzleyin
Open redirect vulnerability in assets/login on the Forescout CounterACT NAC device before 7.0 allows remote attackers to redirect users to a
OrtaCVSS 5,8Kavram kanıtıEPSS %9forescout · counteract5 Ara 2012
- CVE-2024-994923İzleyin
Denial of Service in Forescout SecureConnector
OrtaCVSS 5,8İstismar yokEPSS %0forescout · secureconnector23 Eki 2024
- CVE-2021-3672422İzleyin
ForeScout - SecureConnector Local Service DoS
OrtaCVSS 5,5İstismar yokEPSS %0forescout · secureconnector29 Ara 2021
- CVE-2012-498518İzleyin
The Forescout CounterACT NAC device 6.3.4.1 does not block ARP and ICMP traffic from unrecognized clients, which allows remote attackers to
OrtaCVSS 4,3İstismar yokEPSS %2forescout · counteract5 Ara 2012
- CVE-2012-182517İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in the status program on the ForeScout CounterACT appliance with software 6.3.3.2 throug
OrtaCVSS 4,3İstismar yokEPSS %1forescout · counteract11 Haz 2012
- CVE-2012-498317İzleyin
Multiple cross-site scripting (XSS) vulnerabilities on the Forescout CounterACT NAC device before 7.0 allow remote attackers to inject arbit
OrtaCVSS 4,3İstismar yokEPSS %1forescout · counteract5 Ara 2012