Skip to content
charmnailspa

charmnailspa

Technological development

Primary Menu
  • Computer & Technology
  • internet marketing
  • Web Design
  • Technology
  • computer
  • Business
  • About Us
    • Advertise Here
    • Contact Us
    • Privacy Policy
    • Sitemap
  • Home
  • WatchGuard Plays The Ostrich, Patches Exploit Without Informing Customers
  • Computer & Technology

WatchGuard Plays The Ostrich, Patches Exploit Without Informing Customers

Lisa H. Shelton April 9, 2022

[ad_1]

Table of Contents

Toggle
    • from the heads-in-the-sand dept
  • About the Author
      • Lisa H. Shelton

from the heads-in-the-sand dept

Firewalls. You know, boring old IT stuff. So why are we talking about them at Techdirt? Well, one thing we regularly talk about is how companies tend to respond to exploits and breaches that are uncovered and, far too often, how horrifically bad they are in those responses. Often times, breaches and exploits end up being far more severe than originally reported, and there are some companies that actually try to go after those reporting on breaches and exploits legally.

And then there’s WatchGuard, which was informed in February of 2021 by the FBI that an exploit in one of its firewall lines was being used by Russian hackers to build a botnet, yet the company only patched the exploit out in May of 2021. Oh, and the company didn’t bother to alert its customers of the specifcs in any of this until court documents were unsealed in the past few days revealing the entire issue.

In court documents unsealed on Wednesday, an FBI agent wrote that the WatchGuard firewalls hacked by Sandworm were “vulnerable to an exploit that allows unauthorized remote access to the management panels of those devices.” It wasn’t until after the court document was public that WatchGuard published this FAQ, which for the first time made reference to CVE-2022-23176, a vulnerability with a severity rating of 8.8 out of a possible 10.

The WatchGuard FAQ said that CVE-2022-23176 had been “fully addressed by security fixes that started rolling out in software updates in May 2021.” The FAQ went on to say that investigations by WatchGuard and outside security firm Mandiant “did not find evidence the threat actor exploited a different vulnerability.”

Note that there was an initial response from WatchGuard almost immediately after the advisement from US/UK LEOs, with a tool to let customers identify if they were at risk and instructions for mitigation. Which is all well and good, but customers weren’t given any real specifics as to what the exploit was or how it might be used. That’s the sort of thing IT administrators dig into. The company also basically suggested it was not providing those details to keep the exploit from being more widely used.

When WatchGuard released the May 2021 software updates, the company made only the most oblique of references to the vulnerability.

“These releases also include fixes to resolve internally detected security issues,” a company post stated. “These issues were found by our engineers and not actively found in the wild. For the sake of not guiding potential threat actors toward finding and exploiting these internally discovered issues, we are not sharing technical details about these flaws that they contained.”

Unfortunately, there doesn’t seem to be much that is true in that statement. Law enforcement uncovered the security issue, not some internal WatchGuard team. The exploit was found in the wild, with the FBI assessing that roughly 1% of the firewalls the company sold were compromised with malware called Cyclops Blink, another specific that doesn’t appear to have been communicated to clients.

“As it turns out, threat actors *DID* find and exploit the issues,” Will Dormann, a vulnerability analyst at CERT, said in a private message. He was referring to the WatchGuard explanation from May that the company was withholding technical details to prevent the security issues from being exploited. “And without a CVE issued, more of their customers were exposed than needed to be.

WatchGuard should have assigned a CVE when they released an update that fixed the vulnerability. They also had a second chance to assign a CVE when they were contacted by the FBI in November. But they waited for nearly 3 full months after the FBI notification (about 8 months total) before assigning a CVE. This behavior is harmful, and it put their customers at unnecessary risk.”

And it’s not the kind of thing you can get away with when your business is literally threat detection and prevention in IT. This stinks of a coverup, which is always worse than the crime, cliché though that might be.

Filed Under: botnet, disclosure, fbi, firewall, hackers, security, vulnerability disclosure

Companies: watchguard

[ad_2]

Source link

About the Author

Lisa H. Shelton

Administrator

Visit Website View All Posts

Post navigation

Previous: 6 Easy Computer Games for Beginners
Next: Explainer: Russia’s internet crackdown | Reuters

Related News

The Changing Job Roles in Silicon Valley with AI
  • Computer & Technology

The Changing Job Roles in Silicon Valley with AI

Lisa H. Shelton May 20, 2025
Is AI Really Replacing Jobs in Silicon Valley?
  • Computer & Technology

Is AI Really Replacing Jobs in Silicon Valley?

Lisa H. Shelton May 13, 2025
The Impact of Natural Language Processing on AI
  • Computer & Technology

The Impact of Natural Language Processing on AI

Lisa H. Shelton May 8, 2025
October 2025
M T W T F S S
 12345
6789101112
13141516171819
20212223242526
2728293031  
« Sep    

Archives

  • September 2025
  • May 2025
  • April 2025
  • March 2025
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • March 2020
  • February 2020
  • November 2018
  • October 2018
  • January 2017

Categories

  • Business
  • computer
  • Computer & Technology
  • internet
  • internet marketing
  • Technology
  • Web Design

Recent Posts

  • Wigs for Patients Designed for Natural Beauty
  • Aluminum Fence Installation Port St. Lucie: Elegance, Security, and Lasting Durability
  • The Changing Job Roles in Silicon Valley with AI
  • Is AI Really Replacing Jobs in Silicon Valley?
  • The Impact of Natural Language Processing on AI

Fiverr

Fiverr Logo   

BL

Seedbl

Seedbacklink

Tags

2021 Acura Rdx Technology Package 2021 Acura Tlx Technology Package 2022 Acura Mdx Technology Package Align Technology Stock Applied Racing Technology Artificial Intelligence Technology Solutions Inc Assisted Reproductive Technology Battery Technology Stocks Benjamin Franklin Institute Of Technology Chief Technology Officer Color Star Technology Craft Design Technology Definition Of Technology Definitive Technology Speakers Element Materials Technology Health Information Technology Salary Ice Mortgage Technology Information Technology Definition Information Technology Degree Information Technology Salary Interactive Response Technology International Game Technology Lacrosse Technology Atomic Clock La Crosse Technology Weather Station Luokung Technology Stock Marvell Technology Stock Price Maytag Commercial Technology Washer Microchip Technology Stock Micron Technology Stock Price Mrna Technology History Mrna Vaccine Technology Nyc College Of Technology Penn College Of Technology Recombinant Dna Technology Rlx Technology Stock Robert Half Technology Science And Technology Sharif University Of Technology Smart Home Technology Stevens Institute Of Technology Ranking Symphony Technology Group Technology In The Classroom Technology Readiness Level Technology Stores Near Me Thaddeus Stevens College Of Technology
tourmaxx
cureoly

PONDOK

gemholiday
picrhythm

PL

sitesoke
polizoom

You may have missed

Wigs for Patients Designed for Natural Beauty
  • Technology

Wigs for Patients Designed for Natural Beauty

Lisa H. Shelton September 9, 2025
Aluminum Fence Installation Port St. Lucie: Elegance, Security, and Lasting Durability
  • Technology

Aluminum Fence Installation Port St. Lucie: Elegance, Security, and Lasting Durability

Lisa H. Shelton September 3, 2025
The Changing Job Roles in Silicon Valley with AI
  • Computer & Technology

The Changing Job Roles in Silicon Valley with AI

Lisa H. Shelton May 20, 2025
Is AI Really Replacing Jobs in Silicon Valley?
  • Computer & Technology

Is AI Really Replacing Jobs in Silicon Valley?

Lisa H. Shelton May 13, 2025
charmnailspa.com | MoreNews by AF themes.

WhatsApp us