← Back to CVE List
Vulnerability Intelligence Report
Remote Code injection in Barracuda Email Security Gateway

CVE-2023-2868

A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.001-9.2.0.006. The vulnerability arises out of a failure to comprehensively sanitize the processing of .tar file (tape archives). The vulnerability stems from incomplete input validation of a user-supplied .tar file as it pertains to the names of the files contained within the archive. As a consequence, a remote attacker can specifically format these file names in a particular manner that will result in remotely executing a system command through Perl's qx operator with the privileges of the Email Security Gateway product. This issue was fixed as part of BNSF-36456 patch. This patch was automatically applied to all customer appliances.

CISA KEV SSVC: Active Exploitation Automatable
CVSS Base Score
9.4
CRITICAL
Exploitability:3.9
Impact Score:5.5
EPSS Probability:86.96%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-20 ↗CWE-20 Improper Input Validation

Affected Products & Versions

Vendor Product Affected Versions
Barracuda Barracuda Email Security Gateway 5.1.3.001 < 9.2.0.006 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
86.956%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityGoogle LLC · Vendor · USA
Reserved2023-05-24T14:24:16
Published2023-05-24T18:00:52
Patch Date2023-05-23
Last Updated2025-10-21T23:05:47

LINK COPIED TO CLIPBOARD