Opens in a new tab
vmblog logo 2024 wht (updated)

Firewalls and VPNs Under Fire: Why Businesses Are Shifting to ZTNA

Share: 

David Marshall | Published: May 6, 2024

The past year has seen a particularly alarming trend of vulnerabilities affecting major firewall and VPN vendors, raising serious concerns about the security of traditional remote access solutions.

In this article, I will explore some of the recent CVE (Common Vulnerabilities and Exposures) information and explain why these issues are pushing businesses to consider Zero Trust Network Access (ZTNA) as a more secure alternative to legacy VPN solutions.

Recent Firewall and VPN Vulnerabilities

Here are some examples of recent high-profile CVEs impacting firewall and VPN products:

  • Palo Alto Networks PAN-OS (CVE-2024-3400, April 2024): This critical vulnerability, exploited in the wild, allowed unauthenticated attackers to execute arbitrary code with root privileges on affected firewalls. Palo Alto Networks released patches promptly, but the ease of exploitation and potential consequences highlight the severity of the issue businesses are facing in keeping their workforce secure.
  • Viprinet Multichannel VPN Router (Multiple CVEs, Ongoing): A series of vulnerabilities (including several from 2023) allow attackers to inject malicious scripts or HTML into the VPN Router, potentially leading to credential theft or account compromise.
  • Fortinet FortiOS VPN (CVE-2022-29944): This critical vulnerability from 2022 bypassed authentication, allowing attackers to potentially gain unauthorized access to a network.
  • Pulse Secure Pulse Connect Secure (CVE-2021-30144): This high-severity flaw from 2021 could enable attackers to execute arbitrary code on a vulnerable VPN server, granting complete control over the system. This has led many companies to shut down this remote access solution without an alternative solution in place forcing their users back into offices and causing upset, and frustration.
  • Citrix ADC and Gateway (CVE-2019-19781): This critical vulnerability from 2019 impacted multiple Citrix products, allowing attackers to remotely execute code. Exploiting this vulnerability could have given attackers complete control over the affected systems. Many of the systems in production have still not been patched.

These are just a few examples, and there have been many others that can be found with a quick internet search. These vulnerabilities highlight the inherent security risks associated with relying on perimeter-based security solutions like firewalls and VPNs.

On top of this increased attack surface legacy VPN solutions also have several other flaws making them unfit for us in our new hybrid working world:

  • Complexity: Managing and configuring multiple firewalls and VPNs can be complex, making it difficult to maintain a proper security posture. Configuration mistakes often leave significant gaps in security.
  • Limited Granularity: Traditional solutions often offer limited access control, granting users broad access to a network once authenticated. This “all or nothing” approach creates unnecessary risk.

Why Businesses Are Moving Towards ZTNA

Zero Trust Network Access (ZTNA) offers a more secure approach to remote access by eliminating the concept of implicit trust on the network. Here’s how ZTNA addresses the limitations of traditional solutions:

  • Reduced Attack Surface: ZTNA eliminates the need for VPNs and exposed remote access points. Users only connect to specific applications they require, minimizing the attack surface and potential damage from breaches.
  • Simplified Management: ZTNA solutions are often cloud-based and easier to manage than complex firewall and VPN configurations. This reduces the risk of human error in security configurations.
  • Granular Access Control: ZTNA enforces granular access control, granting users access only to authorized applications and resources based on factors like identity, device, location, and context. This minimizes the potential damage if a breach occurs.

The rise in firewall and VPN vulnerabilities, combined with the benefits of ZTNA, is driving businesses to explore this new approach. ZTNA offers a more secure, manageable, and adaptable solution for today’s dynamic and distributed workforces.

##

ABOUT THE AUTHOR

Jaye Tillson 

Jaye Tillson is Director of Strategy and Field CTO at Axis Security, boasting over 25 years of invaluable expertise in successfully implementing strategic global technology programs. With a strong focus on digital transformation, Jaye has been instrumental in guiding numerous organizations through their zero-trust journey, enabling them to thrive in the ever-evolving digital landscape.

Jaye’s passion lies in collaborating with enterprises, assisting them in their strategic pursuit of zero trust. He takes pride in leveraging his real-world experience to address critical issues and challenges faced by these businesses.

Beyond his professional pursuits, Jaye co-founded the SSE Forum and co-hosts its popular podcast called ‘The Edge.’ This platform allows him to engage with a broader audience, fostering meaningful discussions on industry trends and innovations.