Forescout Technologies maintains a focused portfolio of network access control and device management solutions, particularly SecureConnector and CounterAct, that operate as gatekeepers for enterprise endpoint visibility and policy enforcement. Its vulnerability footprint is modest in volume but concentrated in file-handling and input-validation weakness classes—including improper temporary-file permissions, cross-site scripting, and classic buffer overflows—that reflect the complexity of parsing diverse device types and managing system-level integrations. Current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Forescout Technologies over time
Of all the CVEs published by Forescout Technologies as a CNA, 100.0% affect products that Forescout Technologies develops as a vendor.
Of all the CVEs published that affect products developed by Forescout Technologies, 23.1% are self-published by Forescout Technologies as a CNA.
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-4982MEDIUM Open redirect vulnerability in assets/login on the Forescout CounterACT NAC device before 7.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing | Dec 5, 2012 | 5.8 | 40 | NO | YES |
CVE-2025-4660CRITICAL A remote code execution vulnerability exists in the Windows agent component of SecureConnector due to improper access controls on a named pipe. The pipe is accessible to the Everyo | May 13, 2025 | 9.8 | 30 | NO | NO |
CVE-2023-39374HIGH
ForeScout NAC SecureConnector version 11.2 - CWE-427: Uncontrolled Search Path Element
| Sep 3, 2023 | 7.8 | 23 | NO | NO |
CVE-2021-28098HIGH An issue was discovered in Forescout CounterACT before 8.1.4. A local privilege escalation vulnerability is present in the logging function. SecureConnector runs with administrativ | Apr 14, 2021 | 7.8 | 23 | NO | NO |
CVE-2024-9950HIGH A vulnerability in Forescout SecureConnector v11.3.07.0109 on Windows allows
unauthenticated user to modify compliance scripts due to insecure temporary directory. | Jan 2, 2025 | 7.8 | 22 | NO | NO |
CVE-2021-36724MEDIUM ForeScout - SecureConnector Local Service DoS - A low privilaged user which doesn't have permissions to shutdown the secure connector service writes a large amount of characters in | Dec 29, 2021 | 5.5 | 21 | NO | NO |
CVE-2016-9486HIGH On Windows endpoints, the SecureConnector agent must run under the local SYSTEM account or another administrator account in order to enable full functionality of the agent. The typ | Jul 13, 2018 | 7.8 | 20 | NO | NO |
CVE-2016-9485HIGH On Windows endpoints, the SecureConnector agent must run under the local SYSTEM account or another administrator account in order to enable full functionality of the agent. The typ | Jul 13, 2018 | 7.8 | 20 | NO | NO |
CVE-2024-22795HIGH Insecure Permissions vulnerability in Forescout SecureConnector v.11.3.06.0063 allows a local attacker to escalate privileges via the Recheck Compliance Status component. | Feb 8, 2024 | 7.0 | 19 | NO | NO |
CVE-2024-9949MEDIUM Denial of Service in Forescout SecureConnector 11.1.02.1019 on Windows allows Unprivileged user to corrupt the configuration file and cause Denial of Service in the application. | Oct 23, 2024 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Forescout Technologies.
Media articles that mention a CVE ID that affects a product developed by Forescout Technologies — matched by CVE ID, not by vendor name.