PT-2025-3737 · Forescout · Forescout Secureconnector
Owen Jeanes
·
Published
2025-01-02
·
Updated
2025-10-17
·
CVE-2024-9950
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Forescout SecureConnector version 11.3.07.0109
Description
A vulnerability in Forescout SecureConnector allows unauthenticated users to modify compliance scripts due to an insecure temporary directory. This issue enables unauthorized modification of scripts, potentially leading to security breaches.
Recommendations
For Forescout SecureConnector version 11.3.07.0109, consider restricting access to the temporary directory to prevent unauthorized script modifications until a patch is available. As a temporary workaround, disabling the ability for unauthenticated users to modify compliance scripts can help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Forescout Secureconnector