Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Forescout Technologies

First CVE: Jun 11, 2012Active for: 14 yearsTotal CVEs: 13
34.9
VTI Score
Medium

Forescout Technologies maintains a focused portfolio of network access control and device management solutions, particularly SecureConnector and CounterAct, that operate as gatekeepers for enterprise endpoint visibility and policy enforcement. Its vulnerability footprint is modest in volume but concentrated in file-handling and input-validation weakness classes—including improper temporary-file permissions, cross-site scripting, and classic buffer overflows—that reflect the complexity of parsing diverse device types and managing system-level integrations. Current severity and exploitation activity are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
1.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Forescout Technologies over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 11, 2012
14 years ago
Most Recent CVE
May 13, 2025
437 days ago

Self-Reporting Analysis

Of all the CVEs published by Forescout Technologies as a CNA, 100.0% affect products that Forescout Technologies develops as a vendor.

100.0%
Self-reported: 3 (100.0%)
Third-party: 0 (0.0%)

Of all the CVEs published that affect products developed by Forescout Technologies, 23.1% are self-published by Forescout Technologies as a CNA.

23.1%
76.9%
Self-published: 3 (23.1%)
Other CNAs: 10 (76.9%)

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2012-4982MEDIUM
Open redirect vulnerability in assets/login on the Forescout CounterACT NAC device before 7.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing
Dec 5, 20125.840NOYES
CVE-2025-4660CRITICAL
A remote code execution vulnerability exists in the Windows agent component of SecureConnector due to improper access controls on a named pipe. The pipe is accessible to the Everyo
May 13, 20259.830NONO
CVE-2023-39374HIGH
ForeScout NAC SecureConnector version 11.2 - CWE-427: Uncontrolled Search Path Element
Sep 3, 20237.823NONO
CVE-2021-28098HIGH
An issue was discovered in Forescout CounterACT before 8.1.4. A local privilege escalation vulnerability is present in the logging function. SecureConnector runs with administrativ
Apr 14, 20217.823NONO
CVE-2024-9950HIGH
A vulnerability in Forescout SecureConnector v11.3.07.0109 on Windows allows unauthenticated user to modify compliance scripts due to insecure temporary directory.
Jan 2, 20257.822NONO
CVE-2021-36724MEDIUM
ForeScout - SecureConnector Local Service DoS - A low privilaged user which doesn't have permissions to shutdown the secure connector service writes a large amount of characters in
Dec 29, 20215.521NONO
CVE-2016-9486HIGH
On Windows endpoints, the SecureConnector agent must run under the local SYSTEM account or another administrator account in order to enable full functionality of the agent. The typ
Jul 13, 20187.820NONO
CVE-2016-9485HIGH
On Windows endpoints, the SecureConnector agent must run under the local SYSTEM account or another administrator account in order to enable full functionality of the agent. The typ
Jul 13, 20187.820NONO
CVE-2024-22795HIGH
Insecure Permissions vulnerability in Forescout SecureConnector v.11.3.06.0063 allows a local attacker to escalate privileges via the Recheck Compliance Status component.
Feb 8, 20247.019NONO
CVE-2024-9949MEDIUM
Denial of Service in Forescout SecureConnector 11.1.02.1019 on Windows allows Unprivileged user to corrupt the configuration file and cause Denial of Service in the application.
Oct 23, 20246.118NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
46%
46%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local8 (61.5%)
Network1 (7.7%)
Unknown4 (30.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (61.5%)
High1 (7.7%)
Unknown4 (30.8%)
User Interaction
None7 (53.8%)
Unknown4 (30.8%)
Required2 (15.4%)
Privileges Required
Low6 (46.2%)
High0 (0.0%)
None3 (23.1%)
Unknown4 (30.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
7.7% of CVEs· 96th percentile
ExploitDB
1 CVE
7.7% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Forescout Technologies.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Forescout Technologies — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Forescout Technologies's Products

View all 4 CNAs →

Top CWEs