VendorsForeScoutcounteract6.3.4.10
Vulnerabilities

ForeScout CounterACT 6.3.4.10

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2012-4982
Open redirect vulnerability in assets/login on the Forescout CounterACT NAC device before 7.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the a parameter.
Published 2012-12-05 · Modified
5.81 PoCEPSS 0.089
CVE-2012-4985
The Forescout CounterACT NAC device 6.3.4.1 does not block ARP and ICMP traffic from unrecognized clients, which allows remote attackers to conduct ARP poisoning attacks via crafted packets.
Published 2012-12-05 · Modified
4.3EPSS 0.017
CVE-2012-1825
Multiple cross-site scripting (XSS) vulnerabilities in the status program on the ForeScout CounterACT appliance with software 6.3.3.2 through 6.3.4.10 allow remote attackers to inject arbitrary web script or HTML via (1) the loginname parameter in a forgotpass action or (2) the username parameter.
Published 2012-06-11 · Modified
4.3EPSS 0.010
CVE-2012-4983
Multiple cross-site scripting (XSS) vulnerabilities on the Forescout CounterACT NAC device before 7.0 allow remote attackers to inject arbitrary web script or HTML via (1) the a parameter to assets/login or (2) the query parameter to assets/rangesearch.
Published 2012-12-05 · Modified
4.3EPSS 0.009