Junglewise Threat Intelligence

CVE-2023-2868: Barracuda Networks ESG Appliance Improper Input Validation Vulnerability

CVE-2023-2868 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2023-05-26

Executive brief

A remote command injection vulnerability exists in the Barracuda Email Security Gateway appliance due to improper input validation of filenames within user-supplied .tar archives. An attacker can execute system commands with the privileges of the ESG product via Perl's qx operator by formatting filenames in a specific manner.

Affected products

  • Barracuda Networks Email Security Gateway (ESG) Appliance 5.1.3.001-9.2.0.006

Timeline

  • 2023-05-24: disclosed: NVD Published Date
  • 2023-05-26: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-05-26: advisory: Vendor advisory published