ForeScout NAC SecureConnector – CWE-427: Uncontrolled Search Path Element
CVE-2023-39374

7.8HIGH

Key Information:

Vendor

Forescout

Vendor
CVE Published:
3 September 2023

What is CVE-2023-39374?

The ForeScout NAC SecureConnector version 11.2 is affected by an uncontrolled search path element vulnerability. This issue arises when the application does not properly control the location from which it loads its resources or libraries. Attackers can exploit this flaw to manipulate the search path, potentially leading to the execution of malicious code. Proper remediation steps should be taken to ensure secure configurations and mitigate the risk associated with this type of vulnerability.

Affected Version(s)

NAC SecureConnector version 11.2

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Victor Herrera
.