CVE Vulnerabilities

CVE-2024-9950

Creation of Temporary File in Directory with Insecure Permissions

Published: Jan 02, 2025 | Modified: Oct 17, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability in Forescout SecureConnector v11.3.07.0109 on Windows allows

unauthenticated user to modify compliance scripts due to insecure temporary directory.

Weakness

The product creates a temporary file in a directory whose permissions allow unintended actors to determine the file’s existence or otherwise access that file.

Affected Software

Name Vendor Start Version End Version
Secureconnector Forescout 11.3.07.0109 (including) 11.3.12 (excluding)

Potential Mitigations

References