Below the Surface (Audio) - The Supply Chain Security Podcast

Network Appliances: A Growing Concern - BTS #44

Jan 27, 2025
Chase Snyder, a Director of product marketing with extensive experience in network security, joins to explore the rising threats faced by network appliances, particularly Avanti and Fortinet. He discusses the troubling vulnerabilities that accompany these devices and the urgent need for better security standards. Chase highlights the lack of visibility in network security, making appliances easy targets for attackers. The conversation also delves into the accountability of vendors and emphasizes the necessity for customers to demand improved security practices.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Appliances Are A Growing Attack Surface

  • Many network and security appliances are now a major source of risk because attackers target devices with low visibility.
  • These devices often sit inside critical infrastructure and can enable long-term persistent threats.
ADVICE

Fix Code Quality With Modern SDLC

  • Apply secure development practices like fuzzing and hardened web servers to avoid common memory and command injection bugs.
  • Require vendors to adopt those SDLC practices as part of procurement and compliance checks.
INSIGHT

Recurring, Avoidable Bug Classes

  • The common vulnerability classes in appliances are auth bypass and command execution, which are avoidable with better engineering.
  • The industry knows fixes like fuzzing and improved SDLC but often lacks incentives to apply them.
Get the Snipd Podcast app to discover more snips from this episode
Get the app