I was reviewing the latest security advisories this morning and noticed CVE-2024-20356, which affects CloudGen WAF and Application Gateway firmware versions before 11.0.0. The bulletin states it allows an authenticated, remote attacker to execute arbitrary commands, which is as serious as it gets.
What caught my attention was the vendor's published response. The patch schedule and detailed remediation steps for affected versions are listed as "pending." This creates a difficult situation for admins running those older, but still supported, branches.
* How are others in production environments handling this?
* Are you accelerating plans to upgrade to a fully patched major version, or waiting for a hotfix on your current branch?
* For those evaluating CloudGen, does this transparency (or lack thereof) influence your view of their security response protocols?
I think it's a good moment to discuss how we assess vendor responsiveness to critical vulnerabilities, especially when immediate details are scarce. Sharing your approach might help others formulate a risk mitigation plan while waiting for official guidance.
Keep it constructive.
Oof, "pending" is a rough word to see on a CVE that allows command execution. Been there, staring at a vague timeline while the clock ticks.
My team's rule for this scenario, born from a nasty weekend years back, is if the vuln is severe and public, and the vendor's timeline is fuzzy, we treat the existing version as actively compromised. We accelerate the upgrade to the patched major version, even if it's a bit painful. Waiting for a hotfix on an old branch, when you know the new major version is already fixed, feels too much like gambling. We'd rather manage the known risks of an upgrade than the unknown window of exposure.
That said, this absolutely colors my view of a vendor's response protocol. Transparency about *why* it's pending (e.g., "patch for 10.x is in QA, expected ETA Friday") is okay. Just "pending" with no context feels like being left in the dark, and in security, the dark is where the problems live. Makes me question how they prioritize their supported branches.
it worked on my machine
"Pending" means "you're on your own" in corp-speak. If a hotfix is pending but the next major is already patched, that's your answer. You move now. The risk of a major version jump is calculable. The risk of an RCE with no timeline is not. It's already in the wild.
"Transparency" is a promise they break the second things get hard. Listing it as "pending" is the vendor covering themselves legally while giving you zero operational guidance. It's not transparency, it's a liability shield.
This is how they force major version upgrades. They'll drag their feet on the backport, making your "supported" branch a liability until you cave and move to the new paid version. It's a sales tactic disguised as a security process.
Anyone waiting for that hotfix is betting their company's security on a vendor's goodwill. That's a bad bet.
Just saying.
I agree that the "pending" status puts admins in a very tough spot. While the advice to accelerate a major upgrade is sound, I've seen cases where that jump carries its own stability risks that can't be rushed in a week. So the gamble, as others put it, is choosing between two types of operational risk.
This does influence how I view their security response. Transparency isn't just about admitting a flaw, it's about providing a *manageable* path forward. Even a rough timeline, or a clear statement on whether a hotfix is even being developed for older branches, would help teams make that call.
How do you weigh the immediate stability risks of a major upgrade against the exposure window? For those using CloudGen, do you find their major version upgrades are generally smooth, or do they introduce significant configuration changes that need careful planning?