S4E just found a high top 10 tcp port service scan
medium·Product Based Web Vulnerabilities·Updated Jan 6, 2024

CVE-2012-4982 Scanner

CVE-2012-4982 scanner - Open Redirect vulnerability in Forescout CounterACT NAC device

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.7k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2012-4982
5.8
CVSS

Open redirect vulnerability in assets/login on the Forescout CounterACT NAC device before 7.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the a parameter.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 18, 2026View on NVD →
Detail

The Forescout CounterACT NAC device is a security solution designed to protect enterprise networks from cyber threats. Its primary purpose is to perform network access control, which means that it allows only authorized users and devices to gain access to an organization's network resources. The device can be deployed as a standalone appliance or as a virtual machine on a server.

One of the vulnerabilities detected in the Forescout CounterACT NAC device is the CVE-2012-4982. This vulnerability is an open redirect vulnerability located in assets/login before version 7.0. When exploited, remote attackers can redirect users to arbitrary websites, allowing them to conduct phishing attacks through a URL in the "a" parameter. This vulnerability can be exploited remotely, without the need for any authentication, which poses a significant risk to the organization.

The exploitation of CVE-2012-4982 can lead to several severe impacts for organizations. For instance, attackers can redirect unsuspecting users to phishing websites, which can result in loss of sensitive information such as login credentials. Furthermore, attackers can use this vulnerability to launch attacks such as cross-site scripting (XSS), cross-site request forgery (CSRF), or even to distribute malware to the user's machine or the network.

Thanks to the pro features of the s4e.io platform, users can easily and quickly assess the vulnerability status of their digital assets and gain insights into best practices to protect against cyber threats. With this platform, users can scan their digital assets for vulnerabilities and receive actionable reports that provide detailed information about detected vulnerabilities. Overall, the S4E platform is a valuable tool for organizations that want to ensure the security of their digital assets.

 

REFERENCES

Solution Advice

To protect against CVE-2012-4982, organizations can take the following precautions:

  • Regularly update the Forescout CounterACT NAC device to the latest version or patch for known vulnerabilities
  • Consider using a web application firewall to protect against open redirect attacks
  • Implement input validation and server-side validation to detect and prevent malicious URLs
  • Train employees on how to identify and avoid phishing attacks

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2012-4982 scanner - Open Redirect vulnerability in Forescout CounterACT NAC device S4E