
Below the Surface (Audio) - The Supply Chain Security Podcast Network Appliances: A Growing Concern - BTS #44
Jan 27, 2025
Chase Snyder, a Director of product marketing with extensive experience in network security, joins to explore the rising threats faced by network appliances, particularly Avanti and Fortinet. He discusses the troubling vulnerabilities that accompany these devices and the urgent need for better security standards. Chase highlights the lack of visibility in network security, making appliances easy targets for attackers. The conversation also delves into the accountability of vendors and emphasizes the necessity for customers to demand improved security practices.
AI Snips
Chapters
Transcript
Episode notes
Appliances Are A Growing Attack Surface
- Many network and security appliances are now a major source of risk because attackers target devices with low visibility.
- These devices often sit inside critical infrastructure and can enable long-term persistent threats.
Fix Code Quality With Modern SDLC
- Apply secure development practices like fuzzing and hardened web servers to avoid common memory and command injection bugs.
- Require vendors to adopt those SDLC practices as part of procurement and compliance checks.
Recurring, Avoidable Bug Classes
- The common vulnerability classes in appliances are auth bypass and command execution, which are avoidable with better engineering.
- The industry knows fixes like fuzzing and improved SDLC but often lacks incentives to apply them.
