ABCDEFGHIJKLMNOPQRSTUVWXYZAAABACADAEAF
1
Updated on: Jan-01-2024
2
Number of Vulnerabilities and Average fix time (CVEs)
3
3 Years Critical - 2021-2023
4
Vendor3Y # High/Critical Vulnerabilities3Y Average Days to fix High/Critical
5
Check Point2.001.00
6
PAN32.0029.88
7
Fortinet98.008.95
8
Cisco 92.0022.03
9
10
4 Years - 2020-2023
11
Vendor4 Years Total #4Y Average Time To Fix (days)4Y # Critical Vulnerabilities4Y Average Days to fix High/Critical
12
Check Point3815.762.001.00
13
PAN16254.9479.0059.73
14
Fortinet33931.81103.0016.48
15
Cisco 35735.13142.0047.32
16
17
Total - 2016-2023
18
Vendor# Of VulnerabilitiesAverage Time To Fix (days)# High/CriticalAverage Days to fix High/Critical
19
Check Point6111.6110.002.70
20
PAN29868.41124.0066.08
21
Fortinet54859.94129.0038.58
22
Cisco 56937.64218.0042.33
23
24
Vendor4Y Time2FIX VS. CP4Y #Vuls VS. CP4Y #High/Critical VS. CP4Y Time2FIX
High/Critical VS. CP
Total Time2FIX VS. CPTotal #Vuls VS. CPTotal #High/Critical VS. CPTotal Time2FIX
High/Critical VS. CP
25
Check PointDays Multiplier vs. CP# Multiplier vs. CPAmount Multiplier VS. CPDays Multiplier vs. CPDays Multiplier vs. CP# Multiplier vs. CPAmount Multiplier VS. CPDays Multiplier vs. CP
26
PANx3x4x40x60x6x5x12x24
27
Fortinetx2x9x52x16x5x9x13x14
28
Cisco x2x9x71x47x3x9x22x16
29
30
Total Vulnerabilities per year
31
Vendor
4 Years Total Number of VulnerbilitiesTotal Since 2016Average Per Year Since 201620232022202120202019201820172016
32
Check Point38.0061.007.632622811615
33
PAN162.00298.0037.252324387746163242
34
Fortinet339.00548.0068.508987996476634624
35
Cisco 357.00569.0071.13421377310573455935
36
37
Critical+High Vulnerabilities only
38
Vendor
4 Years Number of High / Critical Vulnerbilities3 Years Number of High / Critical VulnerbilitiesTotal Since 2016Average Per Year Since 201620232022202120202019201820172016
39
Check Point2210.001.2511002312
40
PAN7932124.0015.50292147163719
41
Fortinet10398129.0016.13353231511762
42
Cisco 14292218.0027.251544335024162313
43
44
45
46
47
48
methodology
49
Resource - public advisory of each vendor & OSNIT
50
Total Vul = total CVEs + Vulnerabilities without CVEs
51
Internal vulnerabilities, vulnerabilities fixed before public source/advisory published or no information present = counted as 0 days to fix (same day fix)
52
Vulnerabilities fix date was taken for the 1st version released after the advisory
53
In case of multiple product types, last fixed product family date was taken
54
Informational Alerts/Advisory were not included
55
Non-impact or Disputed CVEs werent included
56
Include only security enterprise products
57
CVE Rating was taken from the vendor site
58
Counted Critical+High based on vendor's own rank
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100