Counteract
Vendor:
First CVE: Jun 11, 2012 · Active for 14 years
5
Total CVEs
More Total CVEs than 77% of tracked products
2.5
Avg CVEs / Year
Higher CVE frequency than 74% of tracked products
5.3
Avg CVSS
Higher Avg CVSS than 10% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Counteract over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 11, 2012
14 years ago
Most Recent CVE
Apr 14, 2021
1,928 days ago
CVE Severity & Scoring
Counteract5 CVEs
80%
20%
All CVEs352,708 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (20.0%)
Network0 (0.0%)
Unknown4 (80.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (20.0%)
High0 (0.0%)
Unknown4 (80.0%)
User Interaction
None0 (0.0%)
Unknown4 (80.0%)
Required1 (20.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (20.0%)
Unknown4 (80.0%)
Top CVEs
Signals from CVEs in this product scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-4982MEDIUM Open redirect vulnerability in assets/login on the Forescout CounterACT NAC device before 7.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing | Dec 5, 2012 | 5.8 | 40 | NO | YES |
CVE-2021-28098HIGH An issue was discovered in Forescout CounterACT before 8.1.4. A local privilege escalation vulnerability is present in the logging function. SecureConnector runs with administrativ | Apr 14, 2021 | 7.8 | 23 | NO | NO |
CVE-2012-4985MEDIUM The Forescout CounterACT NAC device 6.3.4.1 does not block ARP and ICMP traffic from unrecognized clients, which allows remote attackers to conduct ARP poisoning attacks via crafte | Dec 5, 2012 | 4.3 | 17 | NO | NO |
CVE-2012-4983MEDIUM Multiple cross-site scripting (XSS) vulnerabilities on the Forescout CounterACT NAC device before 7.0 allow remote attackers to inject arbitrary web script or HTML via (1) the a pa | Dec 5, 2012 | 4.3 | 17 | NO | NO |
CVE-2012-1825MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in the status program on the ForeScout CounterACT appliance with software 6.3.3.2 through 6.3.4.10 allow remote attackers to inj | Jun 11, 2012 | 4.3 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
20.0% of CVEs· 98th percentile
ExploitDB
1 CVE
20.0% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (5 CVEs).
Media Mentions
Signals from CVEs in this product scope (5 CVEs).
Top CNAs Publishing CVEs For Counteract
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.3.4.10 | 4 | 4.7 | 3.1% | 0 | 1 |
| 6.3.3.2 | 1 | 4.3 | 1.0% | 0 | 0 |