"Tear out Barracuda's stuff and junk them. Replace them with someone's that knows how to make a secure appliance"

Whose, for example? There seems not to be a single vendor that can be relied on to deliver vulnerability-free code. Huawei has taken the public hammering for lousy code, but I bet they're no worse than any other vendor.

The only potential solution at present is defence in depth using kit from multiple vendors, although that's also suspect as they may well use the same buggy O/S libraries. Until the quality of software development reaches adequate standards, no real defence is possible.

