Search

Find a vulnerability

Search criteria

    5 vulnerabilities by forescout

    CVE-2025-4660 (GCVE-0-2025-4660)

    Vulnerability from cvelistv5 โ€“ Published: 2025-05-13 17:34 โ€“ Updated: 2025-08-21 15:14
    VLAI
    Title
    Remote Code Execution in Windows Secure Connector/ย HPS Inspection Engine via Insecure Named Pipe Access
    Summary
    A remote code execution vulnerability exists in the Windows agent component of SecureConnectorย due to improper access controls on a named pipe. The pipe is accessible to the Everyone group and does not restrict remote connections, allowing any network-based attacker to connect without authentication. By interacting with this pipe, an attacker can redirect the agent to communicate with a rogue server that can issue commands via the SecureConnector Agent.ย  This does not impact Linux or OSX Secure Connector.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2025-05-13 18:35 UTC
    CWE
    • CWE-276 - Incorrect Default Permissions
    References
    Impacted products
    Vendor Product Version
    Forescout SecureConnector Affected: 0 , โ‰ค 11.3.6 (custom)
    Unaffected: 11.3.7 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-4660",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-05-13T18:35:04.445621Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-05-13T18:35:12.394Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "Windows"
              ],
              "product": "SecureConnector",
              "vendor": "Forescout",
              "versions": [
                {
                  "lessThanOrEqual": "11.3.6",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "status": "unaffected",
                  "version": "11.3.7",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Pen Test Partners"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003e\n\n\u003c/p\u003e\u003cp\u003eA remote code execution vulnerability exists in the Windows agent component of SecureConnector\u0026nbsp;due to improper access controls on a named pipe. The pipe is accessible to the \u003cstrong\u003eEveryone\u003c/strong\u003e group and does not restrict \u003cstrong\u003eremote connections\u003c/strong\u003e, allowing any network-based attacker to connect without authentication. By interacting with this pipe, an attacker can redirect the agent to communicate with a rogue server that can issue commands via the SecureConnector Agent.\u0026nbsp;\u003cbr\u003e\u003cbr\u003e\n\n\u003cspan style=\"background-color: rgb(24, 26, 27);\"\u003eThis does not impact Linux or OSX Secure Connector. \u003c/span\u003e\n\n\u003cbr\u003e\u003c/p\u003e\n\n\n\u003cp\u003e\u003c/p\u003e"
                }
              ],
              "value": "A remote code execution vulnerability exists in the Windows agent component of SecureConnector\u00a0due to improper access controls on a named pipe. The pipe is accessible to the Everyone group and does not restrict remote connections, allowing any network-based attacker to connect without authentication. By interacting with this pipe, an attacker can redirect the agent to communicate with a rogue server that can issue commands via the SecureConnector Agent.\u00a0\n\n\n\nThis does not impact Linux or OSX Secure Connector."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-549",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-549 Local Execution of Code"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "YES",
                "Recovery": "USER",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "privilegesRequired": "LOW",
                "providerUrgency": "AMBER",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "CONCENTRATED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/AU:Y/R:U/V:C/RE:M/U:Amber",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "MODERATE"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-276",
                  "description": "CWE-276 Incorrect Default Permissions",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-08-21T15:14:15.922Z",
            "orgId": "a14582b7-06f4-4d66-8e82-3d7ba3739e88",
            "shortName": "Forescout"
          },
          "references": [
            {
              "url": "https://forescout.my.site.com/support/s/article/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Remote Code Execution in Windows Secure Connector/\u00a0HPS Inspection Engine via Insecure Named Pipe Access",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a14582b7-06f4-4d66-8e82-3d7ba3739e88",
        "assignerShortName": "Forescout",
        "cveId": "CVE-2025-4660",
        "datePublished": "2025-05-13T17:34:53.955Z",
        "dateReserved": "2025-05-13T17:34:31.059Z",
        "dateUpdated": "2025-08-21T15:14:15.922Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-9950 (GCVE-0-2024-9950)

    Vulnerability from cvelistv5 โ€“ Published: 2025-01-02 15:40 โ€“ Updated: 2025-06-03 13:49
    VLAI
    Title
    Abuse of Unauthenticated Compliance Recheck in SecureConnector
    Summary
    A vulnerability in Forescout SecureConnector v11.3.07.0109ย on Windows allows unauthenticated user to modify compliance scripts due to insecure temporary directory.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2025-01-02 17:37 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    Forescout SecureConnector Affected: v11.3.07.0109 , โ‰ค v11.3.11 (custom)
    Create a notification for this product.
    Date Public
    2024-11-01 21:09
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-9950",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-01-02T17:37:14.368429Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-01-02T17:37:36.857Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "Windows"
              ],
              "product": "SecureConnector",
              "vendor": "Forescout",
              "versions": [
                {
                  "lessThanOrEqual": "v11.3.11",
                  "status": "affected",
                  "version": "v11.3.07.0109",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Owen Jeanes"
            }
          ],
          "datePublic": "2024-11-01T21:09:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A vulnerability in Forescout SecureConnector v11.3.07.0109\u0026nbsp;on Windows allows \n\nunauthenticated user to modify compliance scripts due to insecure temporary directory.\n\n\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u003cbr\u003e\u003c/span\u003e"
                }
              ],
              "value": "A vulnerability in Forescout SecureConnector v11.3.07.0109\u00a0on Windows allows \n\nunauthenticated user to modify compliance scripts due to insecure temporary directory."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-23",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-23 File Content Injection"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "LOCAL",
                "baseScore": 8.5,
                "baseSeverity": "HIGH",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:H/SI:H/SA:H",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-379",
                  "description": "CWE-379",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-06-03T13:49:49.865Z",
            "orgId": "a14582b7-06f4-4d66-8e82-3d7ba3739e88",
            "shortName": "Forescout"
          },
          "references": [
            {
              "url": "https://support.forescout.com/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Abuse of Unauthenticated Compliance Recheck in SecureConnector",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a14582b7-06f4-4d66-8e82-3d7ba3739e88",
        "assignerShortName": "Forescout",
        "cveId": "CVE-2024-9950",
        "datePublished": "2025-01-02T15:40:36.374Z",
        "dateReserved": "2024-10-14T19:24:59.804Z",
        "dateUpdated": "2025-06-03T13:49:49.865Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-9949 (GCVE-0-2024-9949)

    Vulnerability from cvelistv5 โ€“ Published: 2024-10-23 17:37 โ€“ Updated: 2024-11-07 16:36
    VLAI
    Title
    Denial of Service in Forescout SecureConnector
    Summary
    Denial of Service in Forescout SecureConnectorย 11.1.02.1019 on Windows allows Unprivileged user to corrupt the configuration file and cause Denial of Service in the application.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-10-24 14:51 UTC
    CWE
    • CWE-1188 - Insecure Default Initialization of Resource
    Impacted products
    Vendor Product Version
    Forescout SecureConnector Affected: 11.1.02.1019 , โ‰ค 11.3.5 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-9949",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-24T14:51:06.339003Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-24T14:51:20.477Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "Windows"
              ],
              "product": "SecureConnector",
              "vendor": "Forescout",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "11.3.6",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "11.3.5",
                  "status": "affected",
                  "version": "11.1.02.1019",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Denial of Service in Forescout SecureConnector\u0026nbsp;11.1.02.1019 on Windows allows Unprivileged user to corrupt the configuration file and cause Denial of Service in the application.\u0026nbsp;"
                }
              ],
              "value": "Denial of Service in Forescout SecureConnector\u00a011.1.02.1019 on Windows allows Unprivileged user to corrupt the configuration file and cause Denial of Service in the application."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-234",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-234 Hijacking a privileged process"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "HIGH",
                "attackRequirements": "NONE",
                "attackVector": "LOCAL",
                "baseScore": 5.8,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-1188",
                  "description": "CWE-1188 Insecure Default Initialization of Resource",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-11-07T16:36:26.432Z",
            "orgId": "a14582b7-06f4-4d66-8e82-3d7ba3739e88",
            "shortName": "Forescout"
          },
          "references": [
            {
              "url": "https://forescout.my.site.com/support/s/article/High-Severity-Vulnerability-in-Secure-Connector-HPS-Inspection-Engine-v11-3-5-and-lower"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Denial of Service in Forescout SecureConnector",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a14582b7-06f4-4d66-8e82-3d7ba3739e88",
        "assignerShortName": "Forescout",
        "cveId": "CVE-2024-9949",
        "datePublished": "2024-10-23T17:37:42.978Z",
        "dateReserved": "2024-10-14T18:53:58.941Z",
        "dateUpdated": "2024-11-07T16:36:26.432Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-39374 (GCVE-0-2023-39374)

    Vulnerability from cvelistv5 โ€“ Published: 2023-09-03 14:48 โ€“ Updated: 2024-10-01 14:21
    VLAI
    Title
    ForeScout NAC SecureConnector โ€“ CWE-427: Uncontrolled Search Path Element
    Summary
    ForeScout NAC SecureConnector version 11.2 -ย CWE-427: Uncontrolled Search Path Element
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-10-01 14:21 UTC
    CWE
    • CWE-427 - Uncontrolled Search Path Element
    Impacted products
    Vendor Product Version
    ForeScout NAC SecureConnector Unknown: version 11.2 , < Upgrade to Endpoint Module (SecureConnector) Release 1.4.5 (custom)
    Create a notification for this product.
    Date Public
    2023-09-03 13:42
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T18:10:20.296Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.gov.il/en/Departments/faq/cve_advisories"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-39374",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-01T14:21:08.046932Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-01T14:21:15.498Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "NAC SecureConnector",
              "vendor": " ForeScout",
              "versions": [
                {
                  "lessThan": "Upgrade to Endpoint Module (SecureConnector) Release 1.4.5",
                  "status": "unknown",
                  "version": "version 11.2",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Victor Herrera"
            }
          ],
          "datePublic": "2023-09-03T13:42:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\n\n\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eForeScout NAC SecureConnector version 11.2 -\u0026nbsp;\u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eCWE-427: Uncontrolled Search Path Element\u003c/span\u003e\n\n\u003cbr\u003e"
                }
              ],
              "value": "\nForeScout NAC SecureConnector version 11.2 -\u00a0CWE-427: Uncontrolled Search Path Element\n\n\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-427",
                  "description": "CWE-427 Uncontrolled Search Path Element",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-09-03T14:48:58.280Z",
            "orgId": "a57ee1ae-c9c1-4f40-aa7b-cf10760fde3f",
            "shortName": "INCD"
          },
          "references": [
            {
              "url": "https://www.gov.il/en/Departments/faq/cve_advisories"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\n\n\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eUpgrade to Endpoint Module (SecureConnector) Release 1.4.5\u003c/span\u003e\n\n\u003cbr\u003e"
                }
              ],
              "value": "\nUpgrade to Endpoint Module (SecureConnector) Release 1.4.5\n\n\n"
            }
          ],
          "source": {
            "advisory": "ILVN-2023-0131",
            "discovery": "UNKNOWN"
          },
          "title": " ForeScout NAC SecureConnector \u2013 CWE-427: Uncontrolled Search Path Element",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a57ee1ae-c9c1-4f40-aa7b-cf10760fde3f",
        "assignerShortName": "INCD",
        "cveId": "CVE-2023-39374",
        "datePublished": "2023-09-03T14:48:58.280Z",
        "dateReserved": "2023-07-30T10:41:13.579Z",
        "dateUpdated": "2024-10-01T14:21:15.498Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2021-36724 (GCVE-0-2021-36724)

    Vulnerability from cvelistv5 โ€“ Published: 2021-12-29 17:02 โ€“ Updated: 2024-09-16 20:07
    VLAI
    Title
    ForeScout - SecureConnector Local Service DoS
    Summary
    ForeScout - SecureConnector Local Service DoS - A low privilaged user which doesn't have permissions to shutdown the secure connector service writes a large amount of characters in the installationPath. This will cause the buffer to overflow and override the stack cookie causing the service to crash.
    CWE
    • Local Service DoS
    References
    Impacted products
    Vendor Product Version
    ForeScout eServices / eNvoice Affected: SecureConnector 11.0.4.1024
    Create a notification for this product.
    Date Public
    2021-12-28 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T01:01:58.922Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://www.gov.il/en/departments/faq/cve_advisories"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "eServices / eNvoice",
              "vendor": "ForeScout",
              "versions": [
                {
                  "status": "affected",
                  "version": "SecureConnector 11.0.4.1024"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "Alex Katziv - Novartis"
            }
          ],
          "datePublic": "2021-12-28T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "ForeScout - SecureConnector Local Service DoS - A low privilaged user which doesn\u0027t have permissions to shutdown the secure connector service writes a large amount of characters in the installationPath. This will cause the buffer to overflow and override the stack cookie causing the service to crash."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "NONE",
                "baseScore": 6.1,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Local Service DoS",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2021-12-29T17:02:42.000Z",
            "orgId": "a57ee1ae-c9c1-4f40-aa7b-cf10760fde3f",
            "shortName": "INCD"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://www.gov.il/en/departments/faq/cve_advisories"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "HotFix was released"
            }
          ],
          "source": {
            "advisory": "ILVN-2021-0009",
            "defect": [
              "ILVN-2021-0009"
            ],
            "discovery": "EXTERNAL"
          },
          "title": "ForeScout - SecureConnector Local Service DoS",
          "x_generator": {
            "engine": "Vulnogram 0.0.9"
          },
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cna@cyber.gov.il",
              "DATE_PUBLIC": "2021-12-28T11:43:00.000Z",
              "ID": "CVE-2021-36724",
              "STATE": "PUBLIC",
              "TITLE": "ForeScout - SecureConnector Local Service DoS"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "eServices / eNvoice",
                          "version": {
                            "version_data": [
                              {
                                "version_name": "SecureConnector",
                                "version_value": "11.0.4.1024"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "ForeScout"
                  }
                ]
              }
            },
            "credit": [
              {
                "lang": "eng",
                "value": "Alex Katziv - Novartis"
              }
            ],
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "ForeScout - SecureConnector Local Service DoS - A low privilaged user which doesn\u0027t have permissions to shutdown the secure connector service writes a large amount of characters in the installationPath. This will cause the buffer to overflow and override the stack cookie causing the service to crash."
                }
              ]
            },
            "generator": {
              "engine": "Vulnogram 0.0.9"
            },
            "impact": {
              "cvss": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "NONE",
                "baseScore": 6.1,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
                "version": "3.1"
              }
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Local Service DoS"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://www.gov.il/en/departments/faq/cve_advisories",
                  "refsource": "CONFIRM",
                  "url": "https://www.gov.il/en/departments/faq/cve_advisories"
                }
              ]
            },
            "solution": [
              {
                "lang": "en",
                "value": "HotFix was released"
              }
            ],
            "source": {
              "advisory": "ILVN-2021-0009",
              "defect": [
                "ILVN-2021-0009"
              ],
              "discovery": "EXTERNAL"
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a57ee1ae-c9c1-4f40-aa7b-cf10760fde3f",
        "assignerShortName": "INCD",
        "cveId": "CVE-2021-36724",
        "datePublished": "2021-12-29T17:02:42.726Z",
        "dateReserved": "2021-07-12T00:00:00.000Z",
        "dateUpdated": "2024-09-16T20:07:01.981Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }