Executive brief
A remote command injection vulnerability exists in the Barracuda Email Security Gateway appliance due to improper input validation of filenames within user-supplied .tar archives. An attacker can execute system commands with the privileges of the ESG product via Perl's qx operator by formatting filenames in a specific manner.
Affected products
- Barracuda Networks Email Security Gateway (ESG) Appliance 5.1.3.001-9.2.0.006
Timeline
- 2023-05-24: disclosed: NVD Published Date
- 2023-05-26: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
- 2023-05-26: advisory: Vendor advisory published