PT-2025-3737 · Forescout · Forescout Secureconnector

Owen Jeanes

·

Published

2025-01-02

·

Updated

2025-10-17

·

CVE-2024-9950

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Forescout SecureConnector version 11.3.07.0109
Description A vulnerability in Forescout SecureConnector allows unauthenticated users to modify compliance scripts due to an insecure temporary directory. This issue enables unauthorized modification of scripts, potentially leading to security breaches.
Recommendations For Forescout SecureConnector version 11.3.07.0109, consider restricting access to the temporary directory to prevent unauthorized script modifications until a patch is available. As a temporary workaround, disabling the ability for unauthenticated users to modify compliance scripts can help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-9950

Affected Products

Forescout Secureconnector