Forescout Counteract vulnerabilities
5 known vulnerabilities affecting forescout/counteract.
Total CVEs
5
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM4
Vulnerabilities
Page 1 of 1
CVE-2012-4982P4MEDIUMCVSS 5.8PoCv6.3.4.102012-12-05
CVE-2012-4982 [MEDIUM] CWE-20 CVE-2012-4982: Open redirect vulnerability in assets/login on the Forescout CounterACT NAC device before 7.0 allows
Open redirect vulnerability in assets/login on the Forescout CounterACT NAC device before 7.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the a parameter.
nvd
CVE-2021-28098P3HIGHCVSS 7.8fixed in 8.1.42021-04-14
CVE-2021-28098 [HIGH] CWE-59 CVE-2021-28098: An issue was discovered in Forescout CounterACT before 8.1.4. A local privilege escalation vulnerabi
An issue was discovered in Forescout CounterACT before 8.1.4. A local privilege escalation vulnerability is present in the logging function. SecureConnector runs with administrative privileges and writes logs entries to a file in %PROGRAMDATA%\ForeScout SecureConnector\ that has full permissions for the Everyone group. Using a symbolic link allows an a
nvd
CVE-2012-4985P4MEDIUMCVSS 4.3v6.3.4.102012-12-05
CVE-2012-4985 [MEDIUM] CWE-264 CVE-2012-4985: The Forescout CounterACT NAC device 6.3.4.1 does not block ARP and ICMP traffic from unrecognized cl
The Forescout CounterACT NAC device 6.3.4.1 does not block ARP and ICMP traffic from unrecognized clients, which allows remote attackers to conduct ARP poisoning attacks via crafted packets.
nvd
CVE-2012-4983P4MEDIUMCVSS 4.3v6.3.4.102012-12-05
CVE-2012-4983 [MEDIUM] CWE-79 CVE-2012-4983: Multiple cross-site scripting (XSS) vulnerabilities on the Forescout CounterACT NAC device before 7.
Multiple cross-site scripting (XSS) vulnerabilities on the Forescout CounterACT NAC device before 7.0 allow remote attackers to inject arbitrary web script or HTML via (1) the a parameter to assets/login or (2) the query parameter to assets/rangesearch.
nvd
CVE-2012-1825P4MEDIUMCVSS 4.3v6.3.3.2v6.3.4.102012-06-11
CVE-2012-1825 [MEDIUM] CWE-79 CVE-2012-1825: Multiple cross-site scripting (XSS) vulnerabilities in the status program on the ForeScout CounterAC
Multiple cross-site scripting (XSS) vulnerabilities in the status program on the ForeScout CounterACT appliance with software 6.3.3.2 through 6.3.4.10 allow remote attackers to inject arbitrary web script or HTML via (1) the loginname parameter in a forgotpass action or (2) the username parameter.
nvd