CVE-2021-28098
- EPSS 0.05%
- Veröffentlicht 14.04.2021 15:15:14
- Zuletzt bearbeitet 21.11.2024 05:59:05
An issue was discovered in Forescout CounterACT before 8.1.4. A local privilege escalation vulnerability is present in the logging function. SecureConnector runs with administrative privileges and writes logs entries to a file in %PROGRAMDATA%\ForeSc...
CVE-2012-4982
- EPSS 8.92%
- Veröffentlicht 05.12.2012 11:57:15
- Zuletzt bearbeitet 11.04.2025 00:51:21
Open redirect vulnerability in assets/login on the Forescout CounterACT NAC device before 7.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the a parameter.
CVE-2012-4983
- EPSS 0.23%
- Veröffentlicht 05.12.2012 11:57:15
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple cross-site scripting (XSS) vulnerabilities on the Forescout CounterACT NAC device before 7.0 allow remote attackers to inject arbitrary web script or HTML via (1) the a parameter to assets/login or (2) the query parameter to assets/rangesear...
CVE-2012-4985
- EPSS 0.57%
- Veröffentlicht 05.12.2012 11:57:15
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Forescout CounterACT NAC device 6.3.4.1 does not block ARP and ICMP traffic from unrecognized clients, which allows remote attackers to conduct ARP poisoning attacks via crafted packets.
CVE-2012-1825
- EPSS 0.84%
- Veröffentlicht 11.06.2012 23:55:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple cross-site scripting (XSS) vulnerabilities in the status program on the ForeScout CounterACT appliance with software 6.3.3.2 through 6.3.4.10 allow remote attackers to inject arbitrary web script or HTML via (1) the loginname parameter in a ...