CVE-2023-7102

CRITICAL EXPLOITED IN THE WILD

Barracuda ESG Appliance <9.2.1.001 - Parameter Injection

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2023-7102 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io). EIP tracks 1 public exploit from researchers including Mandiant, haile01, Curt Hyvarinen, including a Metasploit module exploits/linux/smtp/barracuda_esg_spreadsheet_rce.

AI-analyzed exploit summary This Metasploit module exploits CVE-2023-7102, a remote code execution vulnerability in Barracuda ESG appliances. It crafts a malicious XLS file with a payload embedded in a FORMAT record, leveraging an unsafe eval() in the Spreadsheet::ParseExcel library to achieve RCE when the ESG scans the attachment.

Description

Use of a Third Party library produced a vulnerability in Barracuda Networks Inc. Barracuda ESG Appliance which allowed Parameter Injection.This issue affected Barracuda ESG Appliance, from 5.1.3.001 through 9.2.1.001, until Barracuda removed the vulnerable logic.

Exploits (1)

metasploit WORKING POC EXCELLENT
by Mandiant, haile01, Curt Hyvarinen · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/smtp/barracuda_esg_spreadsheet_rce.rb

This Metasploit module exploits CVE-2023-7102, a remote code execution vulnerability in Barracuda ESG appliances. It crafts a malicious XLS file with a payload embedded in a FORMAT record, leveraging an unsafe eval() in the Spreadsheet::ParseExcel library to achieve RCE when the ESG scans the attachment.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Barracuda Email Security Gateway (ESG) 5.1.3.001 through 9.2.1.001
No auth needed
Prerequisites: Target email address on the ESG · SMTP access to the ESG appliance
devstral-2 · analyzed May 19, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.4332
EPSS Percentile 98.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2023-12-24
InTheWild.io 2023-12-27
CWE
CWE-1104
Status published
Products (5)
barracuda/email_security_gateway_300_firmware 5.1.3.001 - 9.2.1.001
barracuda/email_security_gateway_400_firmware 5.1.3.001 - 9.2.1.001
barracuda/email_security_gateway_600_firmware 5.1.3.001 - 9.2.1.001
barracuda/email_security_gateway_800_firmware 5.1.3.001 - 9.2.1.001
barracuda/email_security_gateway_900_firmware 5.1.3.001 - 9.2.1.001
Published Dec 24, 2023
Tracked Since Feb 18, 2026