Zero-day in a widely deployed VPN gateway exploited three weeks before the vendor patch
Telemetry suggests a small number of operators used the flaw quietly against government and defence suppliers.
Tomas Berg
Vulnerability Reporter • • 5 min read
An authentication bypass in the appliance's session handler allowed unauthenticated attackers to mint valid tokens for any user. This story is developing and will be updated as our newsroom confirms further detail with affected organisations and responders.
- #Zero-day
- #VPN
- #Exploitation