the Fortigate SSL VPN多个漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

The story began in last August, when we started a new research project on SSL VPN. Compare to the site-to-site VPN such as the IPSEC and PPTP, SSL VPN is more easy to use and compatible with any network environments. For its convenience, SSL VPN becomes the most popular remote access way for enterprise! However, what if this trusted equipment is insecure? It is an important corporate asset but a blind spot of corporation. According to our survey on Fortune 500, the Top-3 SSL VPN vendors dominate about 75% market share. The diversity of SSL VPN is narrow. Therefore, once we find a critical vulnerability on the leading SSL VPN, the impact is huge. There is no way to stop us because SSL VPN must be exposed to the internet. At the beginning of our research, we made a little survey on the CVE amount of leading SSL VPN vendors: ![](https://images.seebug.org/1565839131886-w331s) It seems like Fortinet and Pulse Secure are the most secure ones. Is that true? As a myth buster, we took on...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息