Fortinet, Palo, Checkpoint, Cisco, Sonicwall … is there any big firewall vendor that didn’t have any critical vulnerabilities last year?

  • Ⓜ3️⃣3️⃣ 🌌
    link
    fedilink
    arrow-up
    31
    ·
    1 month ago

    Obsolete binaries not updated for years, hardcoded secrets… this is what you get in firewalls like any other piece of black box equipment.

    • lennivelkant@discuss.tchncs.de
      link
      fedilink
      arrow-up
      21
      ·
      1 month ago

      Security by obscurity may work in delaying exploits, but once someone breaks the obscurity, they have a headstart on exploiting it over those hoping to fix it.

    • cron@feddit.orgOP
      link
      fedilink
      arrow-up
      8
      ·
      1 month ago

      And every service runs as root. This enables the CRL webserver to download /etc/shadow …

      • Ⓜ3️⃣3️⃣ 🌌
        link
        fedilink
        arrow-up
        5
        ·
        1 month ago

        Or user sessions persist on the filesystem so a glitch on the captive portal’s web server allow you to get clear text username and password for currently connected vpn sessions …