Barracuda Vulnerabilities and Affected Products
Vulnerabilities associated with Barracuda Email Security Gateway.
Products
Clear product- Barracuda Email Security Gateway1 vulnerability
- Barracuda Message Archiver1 vulnerability
- Load Balancer ADC1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2023-2868CRITICAL | Remote Code injection in Barracuda Email Security GatewayA remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.001-9.2.0.006. The vulnerability arises out of a failure to comprehensively sanitize the processing of .tar file (tape archives). The vulnerability stems from incomplete input validation of a user-supplied .tar file as it pertains to the names of the files contained within the archive. As a consequence, a remote attacker can specifically format the… | CVSS9.4v3.1 | EPSS87.4% | PoCs5 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |