ZeroHour

CVE-2023-2868

KEVlarge1

Unauthenticated Command Injection in Barracuda Email Security Gateway Appliances via .tar Files

CISA: Barracuda Networks ESG Appliance Improper Input Validation Vulnerability

CVSS 3.1
9.8 critical
EPSS
88%p100
Published
()
KEV added
AI analysis

CVE-2023-2868 is a critical (CVSS 9.8) remote command injection vulnerability in the Barracuda Email Security Gateway (ESG) appliance form factor (models 300, 400, 600, 800 and 900), caused by incomplete input validation of user-supplied .tar archives, specifically the names of the files contained within them. An attacker can deliver a specially crafted .tar file whose internal file names are formatted so that, when the ESG processes the archive, commands are executed through Perl's qx operator. Successful exploitation yields remote command execution with the privileges of the ESG product, and in the observed campaign attackers deployed a backdoor (reported as "SUBMARINE") and persisted on compromised appliances. Only customers running ESG appliances on versions 5.1.3.001 through 9.2.0.006 are affected. Exploitation is confirmed in the wild — CISA added it to the KEV on 2023-05-26, EPSS puts 30-day exploitation probability at 87.7%, and public reporting attributes active exploitation to a Chinese-nexus espionage group (associated in headlines with Salt Typhoon) targeting government, military, and telecom victims; Barracuda's BNSF-36456 patch was applied automatically to customer appliances.

What to do: Verify that each ESG appliance received the automatic BNSF-36456 patch (running fixed firmware at or above 9.2.0.006's successor per vendor instructions), and check appliances for indicators of compromise, including unauthorized command activity and the "SUBMARINE" backdoor, using Barracuda's IOC guidance. Because the espionage campaign established persistence, Barracuda urged full replacement rather than patching of compromised appliances; replace any ESG showing signs of compromise and review email logs for malicious .tar attachments. Limit or monitor internet exposure of ESG management interfaces while remediation proceeds.

Affected
Barracuda Networks Email Security Gateway (ESG) 300 firmware (appliance form factor)5.1.3.001 – 9.2.0.006
Barracuda Networks Email Security Gateway (ESG) 400 firmware (appliance form factor)5.1.3.001 – 9.2.0.006
Barracuda Networks Email Security Gateway (ESG) 600 firmware (appliance form factor)5.1.3.001 – 9.2.0.006
Barracuda Networks Email Security Gateway (ESG) 800 firmware (appliance form factor)5.1.3.001 – 9.2.0.006
Barracuda Networks Email Security Gateway (ESG) 900 firmware (appliance form factor)5.1.3.001 – 9.2.0.006
Estimated exposure
largetens of thousands of deployed ESG appliances (public scans show Barracuda ESGs among commonly internet-exposed email security devices); Barracuda's incident… — The ESG appliance sits on the corporate email perimeter and public scan counts of internet-exposed Barracuda ESG devices run to the tens of thousands, while vendor incident disclosures put the confirmed-compromised subset at on the order…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.001-9.2.0.006. The vulnerability arises out of a failure to comprehensively sanitize the processing of .tar file (tape archives). The vulnerability stems from incomplete input validation of a user-supplied .tar file as it pertains to the names of the files contained within the archive. As a consequence, a remote attacker can specifically format these file names in a particular manner that will result in remotely executing a system command through Perl's qx operator with the privileges of the Email Security Gateway product. This issue was fixed as part of BNSF-36456 patch. This patch was automatically applied to all customer appliances.

CISA Known Exploited Vulnerability
Affected
Barracuda Networks Email Security Gateway (ESG) Appliance
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
barracuda
Products
email security gateway 300 firmware, email security gateway 400 firmware, email security gateway 600 firmware, email security gateway 800 firmware, email security gateway 900 firmware
Weakness
CWE-20, CWE-77
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news