Fortinet, Palo, Checkpoint, Cisco, Sonicwall … is there any big firewall vendor that didn’t have any critical vulnerabilities last year?

    • lennivelkant
      link
      fedilink
      arrow-up
      21
      ·
      2 months ago

      Security by obscurity may work in delaying exploits, but once someone breaks the obscurity, they have a headstart on exploiting it over those hoping to fix it.

    • cron@feddit.orgOP
      link
      fedilink
      arrow-up
      7
      ·
      2 months ago

      And every service runs as root. This enables the CRL webserver to download /etc/shadow …

      • Ⓜ3️⃣3️⃣ 🌌@lemmy.sdf.org
        link
        fedilink
        arrow-up
        5
        ·
        2 months ago

        Or user sessions persist on the filesystem so a glitch on the captive portal’s web server allow you to get clear text username and password for currently connected vpn sessions …