Skip to content
COOEY

EXPOSURES › CVE-2023-2868

CVE-2023-2868

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-05-26 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-2868 ↗
⚡ RCE ◐ ZERO-DAY ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

Barracuda ESG Appliance improper input validation leads to remote command injection.

The Barracuda Email Security Gateway (ESG) appliance contains an improper input validation vulnerability that allows remote command injection. This vulnerability can be exploited by attackers to execute arbitrary commands on the appliance, leading to potential data theft or system compromise. DIB organizations should ensure their ESG appliances are updated to the latest version to mitigate this risk. The vulnerability is actively exploited and has a high embarrassment score due to the potential for remote code execution.

Shame score — The vulnerability is actively exploited and allows for remote command execution, which is a severe risk to the security of the appliance.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Barracuda Email Security Gateway (ESG) appliance contains an improper input validation vulnerability of a user-supplied .tar file, leading to remote command injection.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.