Fortinet SSL-VPN — Pre-auth RCE (CVE-2023-27997)
Asset: VPN gateway exposed on the internet
✓Exposed — SSL-VPN portal, exposed by nature
✓Exploited — pre-auth RCE confirmed in the wild, bypasses MFA
✓Automatable — mass scanning of exposed interfaces, reproducible exploitation
✓Total impact — pre-auth RCE, CVSS 9.1 (rated by Patrowl)
On the BOD 26-04 matrix: patch within 3 days + forensic triage. The top tier.
The telling detail: this CVE dates from 2023. It isn't even a zero-day vulnerability, but a long-known flaw, exposed and actively exploited. That's the heart of the doctrine shift. An old, exposed, exploited asset comes before dozens of high-CVSS "criticals" that, without real exposure, put nothing at risk. Patrowl surfaced and qualified it because it falls under the one variable that's on you, exposure. And moved it to the front of the queue.
Without continuous attack surface mapping, this asset would have stayed a blind spot. You can't meet a 3-day deadline on a gateway you didn't know was exposed. That's what Patrowl's EASM closes. Once the asset is qualified, tracking it against an SLA puts the BOD 26-04 graduated-deadline logic into practice.