4.3
CVSSv2

CVE-2012-4983

Published: 05/12/2012 Updated: 26/02/2013
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities on the Forescout CounterACT NAC device prior to 7.0 allow remote malicious users to inject arbitrary web script or HTML via (1) the a parameter to assets/login or (2) the query parameter to assets/rangesearch.

Vulnerable Product Search on Vulmon Subscribe to Product

forescout counteract 6.3.4.10

Exploits

Forescout NAC (Network Access Control) version 6341 suffers from ICMP and ARP protocols not being filtered, cross site scripting, and cross site redirection vulnerabilities ...