ZeroHour

CVE-2023-7102

CVSS 3.1
9.8 critical
EPSS
45%p99
Published
()
Modified
Description

Use of a Third Party library produced a vulnerability in Barracuda Networks Inc. Barracuda ESG Appliance which allowed Parameter Injection.This issue affected Barracuda ESG Appliance, from 5.1.3.001 through 9.2.1.001, until Barracuda removed the vulnerable logic.

Vendors
barracuda
Products
email security gateway 300 firmware, email security gateway 400 firmware, email security gateway 600 firmware, email security gateway 800 firmware, email security gateway 900 firmware
Weakness
CWE-1104
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news