The team contacted “one of the largest vendors of next generation firewalls” to inform the company of the vulnerability, Cynet CEO Eyal Gruner told SCMagazine.com, and was told, “It is not a flaw. It is by design.”
Cynet did not disclose the specific next generation firewalls that were found to be vulnerable, but Volfus said they tested two different next-generation firewalls that accounted for at least 30 percent of the market, and both were found to contain the same vulnerability. “We can assume that other next-generation firewalls are also affected,” he told SCMagazine.com.
“They understand that it is a security risk,” Volfus said, but said the firewall vendor is not aware of a way to address the problem without losing functionality, such as the web browsing application.
Gruner said the research team discovered the vulnerability while conducting research for clients.

