Secureconnector
Vendor:
First CVE: Jul 13, 2018 · Active for 8 years
8
Total CVEs
More Total CVEs than 87% of tracked products
1.6
Avg CVEs / Year
Higher CVE frequency than 62% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 52% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Secureconnector over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 13, 2018
8 years ago
Most Recent CVE
May 13, 2025
440 days ago
CVE Severity & Scoring
Secureconnector8 CVEs
25%
63%
13%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local7 (87.5%)
Network1 (12.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (87.5%)
High1 (12.5%)
Unknown0 (0.0%)
User Interaction
None7 (87.5%)
Unknown0 (0.0%)
Required1 (12.5%)
Privileges Required
Low6 (75.0%)
High0 (0.0%)
None2 (25.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-4660CRITICAL A remote code execution vulnerability exists in the Windows agent component of SecureConnector due to improper access controls on a named pipe. The pipe is accessible to the Everyo | May 13, 2025 | 9.8 | 30 | NO | NO |
CVE-2023-39374HIGH
ForeScout NAC SecureConnector version 11.2 - CWE-427: Uncontrolled Search Path Element
| Sep 3, 2023 | 7.8 | 23 | NO | NO |
CVE-2024-9950HIGH A vulnerability in Forescout SecureConnector v11.3.07.0109 on Windows allows
unauthenticated user to modify compliance scripts due to insecure temporary directory. | Jan 2, 2025 | 7.8 | 22 | NO | NO |
CVE-2021-36724MEDIUM ForeScout - SecureConnector Local Service DoS - A low privilaged user which doesn't have permissions to shutdown the secure connector service writes a large amount of characters in | Dec 29, 2021 | 5.5 | 21 | NO | NO |
CVE-2016-9486HIGH On Windows endpoints, the SecureConnector agent must run under the local SYSTEM account or another administrator account in order to enable full functionality of the agent. The typ | Jul 13, 2018 | 7.8 | 20 | NO | NO |
CVE-2016-9485HIGH On Windows endpoints, the SecureConnector agent must run under the local SYSTEM account or another administrator account in order to enable full functionality of the agent. The typ | Jul 13, 2018 | 7.8 | 20 | NO | NO |
CVE-2024-22795HIGH Insecure Permissions vulnerability in Forescout SecureConnector v.11.3.06.0063 allows a local attacker to escalate privileges via the Recheck Compliance Status component. | Feb 8, 2024 | 7.0 | 19 | NO | NO |
CVE-2024-9949MEDIUM Denial of Service in Forescout SecureConnector 11.1.02.1019 on Windows allows Unprivileged user to corrupt the configuration file and cause Denial of Service in the application. | Oct 23, 2024 | 6.1 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Secureconnector
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 11.3.06.0063 | 1 | 7.0 | 0.3% | 0 | 0 |
| 11.2 | 1 | 7.8 | 0.2% | 0 | 0 |
| 11.1.02.1019 | 1 | 6.1 | 0.1% | 0 | 0 |
| 11.0.4.1024 | 1 | 5.5 | 0.2% | 0 | 0 |