VPN security flaws could open up your network to attacks

vpn security
Image credit: Shutterstock (Image credit: Shutterstock)

New security flaws discovered in three popular corporate VPN tools by researchers at Devcore could allow attackers to steal confidential information directly from companies' networks.

The firm's Orange Tsai and Meh Chang first discovered the security flaws which affect corporate VPNs from Palo Alto Networks, Fortinet and Pulse Secure.

While consumers utilize VPNs to bypass region blocks and to protect their privacy online, business users often use the services to access resources on their organization's corporate network while working remotely. Typically companies provide their staff with a corporate username and password along with a two-factor authentication code to access their networks using a VPN.

However, according to Chang and Tsai, the flaws they discovered could allow an attacker to gain access to a company's network without the need for a username or password.

SSL VPNs

By using an SSL VPN business users have a convenient way to connect to corporate networks while out of the office but they also provide hackers with an easy way to infiltrate a company's intranet according to Tsai who explained how they can be misused further in a blog post, saying:

“SSL VPNs protect corporate assets from Internet exposure, but what if SSL VPNs themselves are vulnerable? They’re exposed to the Internet, trusted to reliably guard the only way to your intranet. Once the SSL VPN server is compromised, attackers can infiltrate your Intranet and even take over all users connecting to the SSL VPN server!”

The researchers offered further insight on the format string flaw which affects Palo Alto's GlobalProtect portal and GlobalProtect Gateway products in their post. The remote code execution flaw (indexed as CVE-2019-1579) exists in the PAN SSL Gateway and could enable unauthenticated threat actors to remotely execute arbitrary code on target systems if exploited.

Only older versions of the software are affected by the vulnerability but Devcore found that many businesses, including Uber, are still using the outdated software. For example, the researchers found that 22 of Uber's servers were still using a vulnerable version of GlobalProtect.

Palo Alto Networks has alerted its customers regarding the issue in an advisory in which it urged them to update their software to the latest version while Fortinet has updated its firmware to address the vulnerability. Pulse Secure on the other hand, released a patch in April to address the issue.

Via Computing

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in VPN Privacy & Security
PrivadoVPN running on an iPhone during TechRadar's VPN tests
Why PrivadoVPN Free is still a stellar option for streaming
 In this photo illustration a Google Play logo seen displayed on a smartphone.
Why is there so much spyware hidden in the Play Store?
PrivadoVPN running on an iPhone during TechRadar's VPN tests
Why PrivadoVPN Free is still the best free VPN for streaming
Homepage of CloudFlare website on the display of PC, url - CloudFlare.com.
"Network blocking is never going to be the solution" – Cloudflare slams anti-piracy tactics
Panels at RightsCon 2025 during a press briefing about the latest Access Now report of internet shutdowns
2024 was the worst year on record for internet freedoms – again
Vector illustration of the word Censored in a glitch distorted style
Google, Apple, and internet restriction – how Big Tech is making censorship "much worse" according to experts
Latest in News
Apple's Craig Federighi demonstrates the iPhone Mirroring feature of macOS Sequoia at the Worldwide Developers Conference (WWDC) 2024.
Report: iOS 19 and macOS 16 could mark their biggest design overhaul in years – and we have one request
Lego Mario Kart – Mario & Standard Kart set on a shelf.
Lego just celebrated Mario Day in the best way possible, with an incredible Mario Kart set that's up for preorder now
TCL QM7K TV on orange background
TCL’s big, bright new mid-range mini-LED TVs have built-in Bang & Olufsen sound
Apple iPhone 16e
Which affordable phone wins the mid-range race: the iPhone 16e, Nothing 3a, or Samsung Galaxy A56? Our latest podcast tells all
Homepage of Manus, a new Chinese artificial intelligence agent capable of handling complex, real-world tasks, is seen on the screen of an iPhone.
Manus AI may be the new DeepSeek, but initial users report problems
Google Maps
Nightmare Google Maps glitch is deleting timelines, and there isn't a fix yet