• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechFortune 500

Cisco and Fortinet Warn Customers About NSA-Linked Exploits

Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
August 18, 2016, 12:31 PM ET
Fortune Brainstorm TECH 2016
Fortune Brainstorm TECH 2016 WEDNESDAY, JULY 13TH, 2016: ASPEN, CO 9:00 AM A NEW MODEL FOR CONNECTIVITY Chuck Robbins, CEO, Cisco Interviewer: Andrew Nusca, Senior Editor, Fortune PHOTOGRAPH BY STUART ISETT/Fortune Brainstorm TECHStuart Isett

Leaked code that can overcome popular, pervasive computer network firewalls is live and in the wild.

Cisco (CSCO) and Fortinet (FTNT), firewall makers based in the United States, have warned their customers about recently revealed vulnerabilities in their products. The so-called Shadow Brokers, a pseudonymous hacker or group of hackers, this weekend claimed to have stolen these exploits from a top-tier cyberespionage unit known as the Equation Group, which experts have associated with the United States National Security Agency.

The companies issued advisories and, in some cases, fixes or workarounds, after determining—as several computer security researchers had done before them—that some of the exploits worked. Cisco and Fortinet machines were vulnerable to hacking for at least three years, since the portion of files leaked by the Shadow Brokers dated between 2010 and 2013.

Get Data Sheet, Fortune’s technology newsletter.

Cisco, the first to respond, acknowledged that its Adaptive Security Appliances, enterprise-grade networking gear, had holes. The first weakness—a zero-day vulnerability, or previously unknown bug—allowed attackers to remotely execute code on the machines. The exploit was code-named EXTRABACON in the leak.

Cisco published signatures for identifying the attack code, but no patch. Per the advisory: “An attacker could exploit this vulnerability by sending crafted SNMP packets”—or Simple Network Management Protocol data, used for managing devices on a network—”to the affected system,” the company said. “An exploit could allow the attacker to execute arbitrary code and obtain full control of the system or to cause a reload of the affected system.”

One hacker who goes by the alias “XORcat” showed that he was able to disable authentication requirements on a machine using the technique. The exploit “will definitely cause some fatal network heart attacks,” commented Tal Be’ery, a security research manager at Microsoft (MSFT), on Twitter (TWTR).

The second hole—dubbed EPICBANANA in the leak—Cisco had plugged in 2011. The code allowed attackers to crash or run code on its appliances, although they would need access to certain passwords to do so. Despite the attack being five years old, the company issued an advisory “to increase its visibility with our customers,” as Cisco engineer Omar Santos put it in a blog post.

For more on Cisco, watch:

Fortinet also urged its customers to update their devices to defend against an exploit dubbed EGREGIOUSBLUNDER. Specifically, to update their FortiGate firewall firmware to the latest version, 5.0 and above; machines running versions dated earlier than August 2012 are vulnerable to takeover, the company said.

“We are actively working with customers and strongly recommend that all customers running 4.x versions update their systems with the highest priority,” a Fortinet spokesperson wrote in an email to Fortune. “We continue to investigate this exploit and are conducting an additional review of all of our Fortinet products.”

Other companies whose products are mentioned in the NSA-linked exploit leak, such as Juniper Networks (BANANAGLEE) and the Chinese firm TopSec (ELIGIBLEBOMBSHELL), have been slower to react.

A Juniper Networks (JNPR) spokesperson told Fortune a statement that the company is “currently reviewing all available information as related to the disclosures allegedly from the Equation Group, and will analyze any new information that becomes available. If a product vulnerability is identified, we will address the matter and communicate to our customers through our standard Juniper Security Advisory process.”

TopSec, a Chinese manufacturer whose products also mentioned in the leak, has not responded to multiple requests for comment.

The Shadow Brokers’ dump appears to contain dozens of exploits, and the hackers have said that they have even more unreleased files, although no one has been able to verify the claim. If the exploits were stolen off a server used by the NSA (or filched by an insider), as some believe, then the three-year-old bugs—particularly the Cisco zero-day—raise questions about the government’s process for evaluating when and whether to disclose vulnerabilities to the public.

About the Author
Robert Hackett
By Robert Hackett
Instagram iconLinkedIn iconTwitter icon
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Fortune Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

Future of WorkElon Musk
Elon Musk says saving for retirement is irrelevant because AI is going to create a world of abundance: ‘It won’t matter’
By Marco Quiroz-GutierrezJanuary 12, 2026
10 hours ago
vervet
LawAnimals
Monkeys are on the loose in St. Louis, and AI-generated jokes are just slowing down animal control’s primate chase
By Heather Hollingsworth and The Associated PressJanuary 12, 2026
12 hours ago
google
AIApple
‘Apple Intelligence,’ powered by Gemini, marks a ‘major validation moment for Google,’ top tech analyst says
By Michael Liedtke and The Associated PressJanuary 12, 2026
12 hours ago
grok
AISocial Media
Grok blocked in Malaysia and Indonesia as sexual deepfake scandal builds
By Eileen Ng, Edna Tarigan and The Associated PressJanuary 12, 2026
13 hours ago
AIunemployment
‘Godfather of AI’ says the technology will create massive unemployment and send profits soaring — ‘that is the capitalist system’
By Jason MaJanuary 12, 2026
13 hours ago
Cryptocftc
An anonymous Polymarket trader made $400,000 betting on Maduro’s downfall—and now Washington wants answers
By Leo SchwartzJanuary 12, 2026
14 hours ago

Most Popular

placeholder alt text
Economy
‘Sell America’: Investors dump U.S. assets in fear of the end of Fed independence
By Jim EdwardsJanuary 12, 2026
21 hours ago
placeholder alt text
Economy
Treasury spent $276 billion in interest on the national debt in the final three months of 2025, says the CBO—up $30 billion from a year prior
By Eleanor PringleJanuary 12, 2026
20 hours ago
placeholder alt text
Success
An exec at $62 billion giant Colgate says Gen Z workers, despite getting flak for being woke and lazy, are actually ‘pushing us to get better’
By Emma BurleighJanuary 10, 2026
3 days ago
placeholder alt text
AI
This CEO laid off nearly 80% of his staff because they refused to adopt AI fast enough. 2 years later, he says he'd do it again
By Nick LichtenbergJanuary 11, 2026
2 days ago
placeholder alt text
Economy
A Supreme Court ruling that strikes down Trump's tariffs would be the fastest way to revive the stalling job market, top economist says
By Jason MaJanuary 11, 2026
1 day ago
placeholder alt text
Commentary
I run one of America's most successful remote work programs and the critics are right. Their solutions are all wrong, though
By Justin HarlanJanuary 11, 2026
2 days ago

© 2025 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.