Keep your eyes on these

VERY IMPORTANT

Security Articles

RSS

Barracuda Email Security Gateway Appliance (ESG) Vulnerability

released on 2023-05-31 @ 01:46:42 PM
On May 19, 2023, Barracuda Networks identified a remote command injection vulnerability (CVE-2023-2868) present in the Barracuda Email Security Gateway (appliance form factor only) versions 5.1.3.001-9.2.0.006. The vulnerability stemmed from incomplete input validation of user supplied .tar files as it pertains to the names of the files contained within the archive. Consequently, a remote attacker could format file names in a particular manner that would result in remotely executing a system command through Perl's qx operator with the privileges of the Email Security Gateway product.