Hacker ‘handshake’ hole found in common firewalls
NSS Labs tested Cisco, Check Point, Fortinet, Juniper, the Palo Alto Networks, and SonicWall firewalls — Some of the most commonly-used firewalls are subject to a hacker exploit that lets an attacker trick a firewall and get into an internal network as a trusted IP connection.
Context & Ripple Effects
NSS Labs, an independent firewall-testing shop rather than any single vendor's security team, ran the same exploit against firewalls from Cisco, Check Point, Fortinet, Juniper, Palo Alto Networks, and SonicWall — and the TCP handshake trick worked broadly, letting an attacker enter an internal network dressed as a trusted IP connection. With no prior corpus coverage on this beat, the significance rests on the breadth: this is not one vendor's bug but a shared weakness in how the entire category adjudicates trust at connection setup.
That framing matters because firewall purchases in 2011 lean heavily on vendor claims and certification-style benchmarks; a lab result showing a class-wide hole puts the testing organizations themselves, not just the vendors, at the center of enterprise buying decisions.
First-order effects
- Enterprises running any of the six tested firewalls must treat their perimeter trust boundary as porous to handshake spoofing until their vendor issues guidance or fixes, making immediate triage a security-team task rather than a procurement one.
- Cisco, Check Point, Fortinet, Juniper, Palo Alto Networks, and SonicWall each face pressure to publicly characterize whether their implementations are exploitable and on what remediation timeline, since a collective silence reads as confirmation.
Second-order effects
- Independent test houses like NSS Labs gain leverage over firewall procurement, as buyers weighing competing products start discounting vendor self-attestation in favor of adversarial third-party results.
- Vendors may differentiate on detection depth beyond connection-level checks — application-layer inspection and identity-aware policies become selling points precisely because handshake-level trust proved spoofable.
Third-order effects
- If a single protocol-level flaw spans the whole incumbent field, it argues that perimeter firewalls acting as trusted gatekeepers are structurally brittle, pushing enterprise architecture toward layered verification where no single device's verdict on a connection is final.
The trend: Enterprise network security is drifting from trusting connection-level firewall verdicts toward verifying every session independently, with third-party lab testing increasingly setting the terms of vendor credibility.