Re: Cisco October 2024 Cisco ASA, FMC, and FTD Software Security Advisory Bundled Publication
Trying to deflect attention away from Fortinet - Fine.
All software has vulnerabilities. The important things are:
1. Having a secure SDLC in place to prevent security issues from reaching customers, and
2. HOW YOU RESPOND when one does slip through. (Responsible disclosure AND 0-Day response.)
Fortinet and others are not looking good on those two metrics, and trend over time is not moving in the right direction...!
This is an industry-wide problem, not just related to Firewalls, etc, and will continue until either:
A. RFP's start to exclude bidders based on CVE's and response times, or
B. Cyber Insurance can be invalidated or be more expensive if an incumbent vendor has a poor record of developing secure code / responding to CVE's.