EXPOSURES › CVE-2023-2868
CVE-2023-2868
HIGH ⌖ ON CISA KEV · EXPLOITEDBarracuda ESG Appliance improper input validation leads to remote command injection.
The Barracuda Email Security Gateway (ESG) appliance contains an improper input validation vulnerability that allows remote command injection. This vulnerability can be exploited by attackers to execute arbitrary commands on the appliance, leading to potential data theft or system compromise. DIB organizations should ensure their ESG appliances are updated to the latest version to mitigate this risk. The vulnerability is actively exploited and has a high embarrassment score due to the potential for remote code execution.
Shame score — The vulnerability is actively exploited and allows for remote command execution, which is a severe risk to the security of the appliance.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Barracuda Email Security Gateway (ESG) appliance contains an improper input validation vulnerability of a user-supplied .tar file, leading to remote command injection.