« Back to list

Barracuda

Barracuda Email Security Gateway 400 Firmware: vulnerabilities and CVEs

Barracuda Email Security Gateway 400 Firmware has 2 published vulnerabilities, 0 of them in the last 12 months. 2 are rated critical and 1 are listed by CISA as actively exploited.

CVEs2
Last 12 months0
Critical2
Actively exploited1

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2023-2868Critical (9.8)88%⚠ Active exploitationMay 24, 2023
A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.001-9.2.0.006. The vulnerability arises out of a failure to…

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2023-7102Critical (9.8)45%—Dec 24, 2023
Use of a Third Party library produced a vulnerability in Barracuda Networks Inc. Barracuda ESG Appliance which allowed Parameter Injection.This issue affected Barracuda ESG Appliance, from 5.1.3.001 through 9.2.1.001,…
CVE-2023-2868Critical (9.8)88%⚠ Active exploitationMay 24, 2023
A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.001-9.2.0.006. The vulnerability arises out of a failure to…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059 Command and Scripting Interpreter1
  2. T1190 Exploit Public-Facing Application1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Barracuda