Record summary

CVE-2012-4982 has a selected CVSS score of 5.8; EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

Open redirect vulnerability in assets/login on the Forescout CounterACT NAC device before 7.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the a parameter.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Proofs of concept

1

Catalogued exploits

ExploitDBForescout CounterACT - 'a' Open RedirectionExploitDB exploitby Joseph SheridanNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMForescout CounterACT 6.3.4.1 - Open RedirectCVSS 5.8

Open redirect vulnerability in assets/login on the Forescout CounterACT NAC device before 7.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the 'a' parameter.

Impact

An attacker can exploit this vulnerability to redirect users to malicious websites, leading to phishing attacks or the download of malware.

Remediation

Apply the latest security patches or upgrade to a newer version of Forescout CounterACT to fix the open redirect vulnerability.

WeaknessesCWE-20
Authorsctflearner
Template tagscvecve2012redirectforescoutcounteractvuln
CVSS vector: CVSS:2.0/AV:N/AC:M/Au:N/C:P/I:P/A:N
CPE: cpe:2.3:a:forescout:counteract:6.3.4.10:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

3