SSL-VPN and remote-access gateway appliances concentrate risk: they are internet-facing by design, they hold a route into the internal network, and they run large, closed firmware stacks that have proven rich in vulnerabilities. The result is that their pre-authentication flaws, path traversal, authentication bypass, command injection, and memory corruption reachable on the web portal, are the single most consequential initial-access vector of recent years, exploited at scale by ransomware and state actors. Each major product has had unauthenticated chains: Fortinet FortiOS, Ivanti Connect Secure, Palo Alto GlobalProtect, Citrix Gateway, and Cisco ASA. The method is always to fingerprint the product and build, then match it to its known pre-auth exploit.
curl -skI https://<gateway>/ # product/headers
curl -sk https://<gateway>/ | grep -iE 'fortigate|ivanti|pulse|globalprotect|netscaler|citrix|anyconnect'
Subtopics#
- Fortinet FortiOS: FortiGate SSL-VPN path traversal and heap RCE.
- Ivanti Connect Secure: auth-bypass plus command-injection chains.
- Palo Alto GlobalProtect: GlobalProtect/PAN-OS unauthenticated RCE.
- Citrix Gateway: traversal-to-RCE and the Citrix Bleed token disclosure.
- Cisco ASA and AnyConnect: WebVPN traversal and portal credential attacks.