CVE-2019-6724

HIGH

Barracuda VPN Client < 5.0.2.7 - Untrusted Search Path via barracudavpn Component

Title source: llm
STIX 2.1

Description

The barracudavpn component of the Barracuda VPN Client prior to version 5.0.2.7 for Linux, macOS, and OpenBSD runs as a privileged process and can allow an unprivileged local attacker to load a malicious library, resulting in arbitrary code executing as root.

Scores

CVSS v3 7.8
EPSS 0.0052
EPSS Percentile 39.8%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-426
Status published
Products (1)
barracuda/vpn_client < 5.0.2.7
Published Mar 21, 2019
Tracked Since Feb 18, 2026