Skip to content
Notifications
Clear all

Breaking: New CVE for a similar SDP product. Should we audit Appgate?

4 Posts
4 Users
0 Reactions
2 Views
(@eval_rookie_42)
Reputable Member
Joined: 4 months ago
Posts: 158
Topic starter   [#16695]

I just saw a CVE disclosure for a different SDP provider. It mentioned a vulnerability in their access gateway. Since we're evaluating Appgate SDP, this has me concerned.

We're in the early stages of our zero-trust project. Should we proactively ask Appgate about their audit reports or penetration testing results? What specific areas should we check, given this other vendor's issue? I want to make sure we're not overlooking a similar risk.



   
Quote
(@henry)
Estimable Member
Joined: 1 week ago
Posts: 79
 

Absolutely ask for their pentest reports and security audit history. Any vendor in this space should be ready to share that during a serious evaluation.

Given the other CVE was about the access gateway, I'd specifically ask about their testing around the controller and gateway components. How often do they do external assessments? Can you see a recent report summary?

It's a good way to gauge how transparent they are. If they balk, that's a red flag for me.


Cheers, Henry


   
ReplyQuote
(@isabellaw)
Eminent Member
Joined: 6 days ago
Posts: 21
 

Completely agree that asking for pentest reports is a good move. Transparency is huge.

One thing I'd add - when you ask, maybe request a sanitized example or a summary page. I've been in procurement for financial systems before, and a full report sometimes contains details the vendor can't share. But they should absolutely be able to provide a summary letter from the testing firm, the scope, and the high-level findings, especially for the gateway and controller modules.

Also, "how often do they do external assessments" is the perfect question. Annual is okay, but quarterly or tied to every major release is much better in my opinion. It shows it's baked into their process, not just a check-box for sales.

If they're hesitant, do you think asking for their compliance certifications (like SOC 2) would be a good alternative, or does that not cover the same technical ground?



   
ReplyQuote
(@ci_cd_plumber)
Reputable Member
Joined: 3 months ago
Posts: 156
 

Yes, you should absolutely ask. A CVE for a competing product is a clear trigger for your own due diligence.

When you reach out, don't just ask for generic reports. Specifically reference the other CVE and ask Appgate if their gateway component has been tested for similar attack vectors, like unauthorized access bypass or memory corruption in session handling. Their answer will tell you a lot about their security posture.

Also, ask for the timeline. When was their last full external pen test? If it was over a year ago, that's a problem. These products evolve fast. You need to know their testing cadence is tied to releases, not just an annual compliance exercise.


Build once, deploy everywhere


   
ReplyQuote