Vulnerabilities
13 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-34392 | Unauthenticated RCE in Barracuda RMM Service Center via unverified WSDL URLs Barracuda Service Center, the service-management component implemented in the Barracuda RMM solution, in versions prior to 2025.1.1 does not verify the URL defined in an attacker-controlled WSDL document before the application loads it, an issue classed as absolute path traversal (CWE-36) and detailed in watchtowr's 'SOAPwn' research on .NET Framework WSDL/HTTP-client-proxy handling. An unauthenticated network attacker who can supply or influence the WSDL processed by the application can direct it to load content from an attacker-controlled URL, resulting in arbitrary file write on the server, including upload of a webshell, and ultimately remote code execution. Successful exploitation carries high impact to confidentiality, integrity and availability (CVSS v4.0 score 10.0, critical), against the RMM server and potentially the downstream environments it manages. Organizations running Barracuda RMM with the affected Service Center component before 2025.1.1 — typically managed service providers and the customers they manage — are affected. No confirmed in-the-wild exploitation has been reported (not in CISA KEV), but a public proof-of-concept exists and EPSS assigns a 24.7% probability of exploitation within 30 days (98th percentile), indicating elevated risk. Do: Upgrade Barracuda RMM to version 2025.1.1 or later, which resolves this flaw. Until patched, restrict network access to the Barracuda Service Center component and review the hosting server for unexpected file writes or webshells (e.g., in web-accessible directories), given the elevated EPSS probability. Details on the exploitation technique are available in watchtowr's public 'SOAPwn' write-up. | 10.0 group max | 25% | PoC |
| — | |
| CVE-2025-8319 | the BMA login interface allows arbitrary JavaScript or HTML to be written straight into the page’s Document Object Model via the error= URL parameter the BMA login interface allows arbitrary JavaScript or HTML to be written straight into the page’s Document Object Model via the error= URL parameter NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2023-7102 | Use of a Third Party library produced a vulnerability in Barracuda Networks Inc. Use of a Third Party library produced a vulnerability in Barracuda Networks Inc. Barracuda ESG Appliance which allowed Parameter Injection.This issue affected Barracuda ESG Appliance, from 5.1.3.001 through 9.2.1.001, until Barracuda removed the vulnerable logic. NVD description · AI analysis pending | 9.8 | 45% |
| — | ||
| CVE-2023-2868 | Unauthenticated Command Injection in Barracuda Email Security Gateway Appliances via .tar Files CVE-2023-2868 is a critical (CVSS 9.8) remote command injection vulnerability in the Barracuda Email Security Gateway (ESG) appliance form factor (models 300, 400, 600, 800 and 900), caused by incomplete input validation of user-supplied .tar archives, specifically the names of the files contained within them. An attacker can deliver a specially crafted .tar file whose internal file names are formatted so that, when the ESG processes the archive, commands are executed through Perl's qx operator. Successful exploitation yields remote command execution with the privileges of the ESG product, and in the observed campaign attackers deployed a backdoor (reported as "SUBMARINE") and persisted on compromised appliances. Only customers running ESG appliances on versions 5.1.3.001 through 9.2.0.006 are affected. Exploitation is confirmed in the wild — CISA added it to the KEV on 2023-05-26, EPSS puts 30-day exploitation probability at 87.7%, and public reporting attributes active exploitation to a Chinese-nexus espionage group (associated in headlines with Salt Typhoon) targeting government, military, and telecom victims; Barracuda's BNSF-36456 patch was applied automatically to customer appliances. Do: Verify that each ESG appliance received the automatic BNSF-36456 patch (running fixed firmware at or above 9.2.0.006's successor per vendor instructions), and check appliances for indicators of compromise, including unauthorized command activity and the "SUBMARINE" backdoor, using Barracuda's IOC guidance. Because the espionage campaign established persistence, Barracuda urged full replacement rather than patching of compromised appliances; replace any ESG showing signs of compromise and review email logs for malicious .tar attachments. Limit or monitor internet exposure of ESG management interfaces while remediation proceeds. | 9.8 | 88% | KEV |
| largetens of thousands of deployed ESG appliances (public scans show Barracuda ESGs among commonly internet-exposed email security devices); Barracuda's incident… | |
| CVE-2023-26213 | On Barracuda CloudGen WAN Private Edge Gateway devices before 8 webui-sdwan-1089-8.3.1-174141891, an OS command injection vulnerability exists in /ajax/update_c On Barracuda CloudGen WAN Private Edge Gateway devices before 8 webui-sdwan-1089-8.3.1-174141891, an OS command injection vulnerability exists in /ajax/update_certificate - a crafted HTTP request allows an authenticated attacker to execute arbitrary commands. For example, a name field can contain :password and a password field can contain shell metacharacters. NVD description · AI analysis pending | 7.2 | 8% | PoC ×2 |
| — | |
| CVE-2021-42711 | Barracuda Network Access Client before 5.2.2 creates a Temporary File in a Directory with Insecure Permissions. Barracuda Network Access Client before 5.2.2 creates a Temporary File in a Directory with Insecure Permissions. This file is executed with SYSTEM privileges when an unprivileged user performs a repair operation. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2019-5648 | Authenticated, administrative access to a Barracuda Load Balancer ADC running unpatched firmware <= v6.4 allows one to edit the LDAP service configuration of th Authenticated, administrative access to a Barracuda Load Balancer ADC running unpatched firmware <= v6.4 allows one to edit the LDAP service configuration of the balancer and change the LDAP server to an attacker-controlled system, without having to re-enter LDAP credentials. These steps can be used by any authenticated administrative user to expose the LDAP credentials configured in the LDAP connector over the network. NVD description · AI analysis pending | 6.5 | 1% | PoC |
| — | |
| CVE-2019-6724 | The barracudavpn component of the Barracuda VPN Client prior to version 5.0.2.7 for Linux, macOS, and OpenBSD runs as a privileged process and can allow an unpr The barracudavpn component of the Barracuda VPN Client prior to version 5.0.2.7 for Linux, macOS, and OpenBSD runs as a privileged process and can allow an unprivileged local attacker to load a malicious library, resulting in arbitrary code executing as root. NVD description · AI analysis pending | 7.8 | <1% | PoC |
| — | |
| CVE-2018-20369 | Barracuda Message Archiver 2018 has XSS in the error_msg exception-handling value for the ldap_user parameter to the cgi-mod/ldap_load_entry.cgi module. Barracuda Message Archiver 2018 has XSS in the error_msg exception-handling value for the ldap_user parameter to the cgi-mod/ldap_load_entry.cgi module. The injection point of the issue is the Add_Update module. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2017-6320 | A remote command injection vulnerability exists in the Barracuda Load Balancer product line (confirmed on v5.4.0.004 (2015-11-26) and v6.0.1.006 (2016-08-19); A remote command injection vulnerability exists in the Barracuda Load Balancer product line (confirmed on v5.4.0.004 (2015-11-26) and v6.0.1.006 (2016-08-19); fixed in 6.1.0.003 (2017-01-17)) in which an authenticated user can execute arbitrary shell commands and gain root privileges. The vulnerability stems from unsanitized data being processed in a system call when the delete_assessment command is issued. NVD description · AI analysis pending | 8.8 | 11% | PoC |
| — |