CVE-2023-2868
Last modified
CVE-2023-2868 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.001-9.2.0.006. The vulnerability arises out of a failure to comprehensively sanitize the processing of .tar file (tape archives). The vulnerability stems from incomplete input validation of a user-supplied .tar file as it pertains to the names of the files contained within the archive. CISA has confirmed active exploitation in the wild. EPSS estimates a 86.96% chance of exploitation in the next 30 days.
Description
A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.001-9.2.0.006. The vulnerability arises out of a failure to comprehensively sanitize the processing of .tar file (tape archives). The vulnerability stems from incomplete input validation of a user-supplied .tar file as it pertains to the names of the files contained within the archive. As a consequence, a remote attacker can specifically format these file names in a particular manner that will result in remotely executing a system command through Perl's qx operator with the privileges of the Email Security Gateway product. This issue was fixed as part of BNSF-36456 patch. This patch was automatically applied to all customer appliances.
Metrics
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Barracuda | Email Security Gateway 300 Firmware | >= 5.1.3.001, <= 9.2.0.006 |
| Barracuda | Email Security Gateway 400 Firmware | >= 5.1.3.001, <= 9.2.0.006 |
| Barracuda | Email Security Gateway 600 Firmware | >= 5.1.3.001, <= 9.2.0.006 |
| Barracuda | Email Security Gateway 800 Firmware | >= 5.1.3.001, <= 9.2.0.006 |
| Barracuda | Email Security Gateway 900 Firmware | >= 5.1.3.001, <= 9.2.0.006 |
References
- https://status.barracuda.com/incidents/34kx82j5n4q9Vendor Advisory
- https://www.barracuda.com/company/legal/esg-vulnerabilityMitigation, Vendor Advisory
- https://status.barracuda.com/incidents/34kx82j5n4q9Vendor Advisory
- https://www.barracuda.com/company/legal/esg-vulnerabilityMitigation, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-2868US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2023-2868?
How severe is CVE-2023-2868?
How do I fix CVE-2023-2868?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-28674A cross-site request forgery (CSRF) vulnerability in Jenkins…8.8
- CVE-2023-28675A missing permission check in Jenkins OctoPerf Load Testing …4.3
- CVE-2023-28676A cross-site request forgery (CSRF) vulnerability in Jenkins…8.8
- CVE-2023-28677Jenkins Convert To Pipeline Plugin 1.0 and earlier uses basi…9.8
- CVE-2023-28678Jenkins Cppcheck Plugin 1.26 and earlier does not escape fil…5.4
- CVE-2023-28679Jenkins Mashup Portlets Plugin 1.1.2 and earlier provides th…5.4
- CVE-2023-28680Jenkins Crap4J Plugin 0.9 and earlier does not configure its…7.5
- CVE-2023-28681Jenkins Visual Studio Code Metrics Plugin 1.7 and earlier do…8.2
- CVE-2023-28682Jenkins Performance Publisher Plugin 8.09 and earlier does n…8.2
- CVE-2023-28683Jenkins Phabricator Differential Plugin 2.1.5 and earlier do…8.2
- CVE-2023-28684Jenkins remote-jobs-view-plugin Plugin 0.0.3 and earlier doe…6.5
- CVE-2023-28685Jenkins AbsInt a³ Plugin 1.1.0 and earlier does not configur…7.1
Are you affected by CVE-2023-2868?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
