CVE-2023-7102

CRITICAL EXPLOITED IN THE WILD

Barracuda ESG Appliance <9.2.1.001 - Parameter Injection

Title source: llm
STIX 2.1

Description

Use of a Third Party library produced a vulnerability in Barracuda Networks Inc. Barracuda ESG Appliance which allowed Parameter Injection.This issue affected Barracuda ESG Appliance, from 5.1.3.001 through 9.2.1.001, until Barracuda removed the vulnerable logic.

Scores

CVSS v3 9.8
EPSS 0.0891
EPSS Percentile 92.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2023-12-24
InTheWild.io 2023-12-27
CWE
CWE-1104
Status published
Products (5)
barracuda/email_security_gateway_300_firmware 5.1.3.001 - 9.2.1.001
barracuda/email_security_gateway_400_firmware 5.1.3.001 - 9.2.1.001
barracuda/email_security_gateway_600_firmware 5.1.3.001 - 9.2.1.001
barracuda/email_security_gateway_800_firmware 5.1.3.001 - 9.2.1.001
barracuda/email_security_gateway_900_firmware 5.1.3.001 - 9.2.1.001
Published Dec 24, 2023
Tracked Since Feb 18, 2026