The Forescout CounterACT NAC device 6.3.4.1 does not block ARP and ICMP traffic from unrecognized clients, which allows remote attackers to conduct ARP poisoning attacks via crafted packets.
References
Configurations
History
21 Nov 2024, 01:43
Type | Values Removed | Values Added |
---|---|---|
References | () http://osvdb.org/87895 - | |
References | () http://www.reactionpenetrationtesting.co.uk/forescout-nac-icmp-arp.html - | |
References | () http://www.securityfocus.com/bid/56689 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/80284 - |
Information
Published : 2012-12-05 11:57
Updated : 2024-11-21 01:43
NVD link : CVE-2012-4985
Mitre link : CVE-2012-4985
CVE.ORG link : CVE-2012-4985
JSON object : View
Products Affected
forescout
- counteract
CWE
CWE-264
Permissions, Privileges, and Access Controls