ZeroHour
The Recordpublished ()ingested

Barracuda Networks issue added to CISA vulnerability list

highVulnerability exploited in the wildimportance 60CVE-2023-2868

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-2868
Unauthenticated Command Injection in Barracuda Email Security Gateway Appliances via .tar Files

CVE-2023-2868 is a critical (CVSS 9.8) remote command injection vulnerability in the Barracuda Email Security Gateway (ESG) appliance form factor (models 300, 400, 600, 800 and 900), caused by incomplete input validation of user-supplied .tar archives, specifically the names of the files contained within them. An attacker can deliver a specially crafted .tar file whose internal file names are formatted so that, when the ESG processes the archive, commands are executed through Perl's qx operator. Successful exploitation yields remote command execution with the privileges of the ESG product, and in the observed campaign attackers deployed a backdoor (reported as "SUBMARINE") and persisted on compromised appliances. Only customers running ESG appliances on versions 5.1.3.001 through 9.2.0.006 are affected. Exploitation is confirmed in the wild — CISA added it to the KEV on 2023-05-26, EPSS puts 30-day exploitation probability at 87.7%, and public reporting attributes active exploitation to a Chinese-nexus espionage group (associated in headlines with Salt Typhoon) targeting government, military, and telecom victims; Barracuda's BNSF-36456 patch was applied automatically to customer appliances.

Do: Verify that each ESG appliance received the automatic BNSF-36456 patch (running fixed firmware at or above 9.2.0.006's successor per vendor instructions), and check appliances for indicators of compromise, including unauthorized command activity and the "SUBMARINE" backdoor, using Barracuda's IOC guidance. Because the espionage campaign established persistence, Barracuda urged full replacement rather than patching of compromised appliances; replace any ESG showing signs of compromise and review email logs for malicious .tar attachments. Limit or monitor internet exposure of ESG management interfaces while remediation proceeds.

9.888% KEV
  • Barracuda Networks Email Security Gateway (ESG) 300 firmware (appliance form factor) 5.1.3.001 – 9.2.0.006
  • Barracuda Networks Email Security Gateway (ESG) 400 firmware (appliance form factor) 5.1.3.001 – 9.2.0.006
  • Barracuda Networks Email Security Gateway (ESG) 600 firmware (appliance form factor) 5.1.3.001 – 9.2.0.006
  • +2 more
largetens of thousands of deployed ESG appliances (public scans show Barracuda ESGs among commonly internet-exposed email security devices); Barracuda's incident…
Full article236 words · extracted from therecord.media · click to collapse

A bug patched recently in email security hardware from Barracuda Networks was added Friday to the federal catalog of exploited vulnerabilities.

The company reported earlier this week that it pushed out two separate patches to its Email Security Gateway (ESG) appliance to fix a flaw “in a module which initially screens the attachments of incoming emails.”

The bug could allow an attacker to remotely execute system commands, according to the entry in the government’s Known Exploited Vulnerabilities database.

In posting the bug, tracked as CVE-2023-2868, the Cybersecurity and Infrastructure Security Agency warned federal agencies and the public that these types of vulnerabilities “are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.”

Barracuda Networks says it serves more than 200,000 customers worldwide, most of them small- and medium-sized enterprises. It did not report how many of the ESG appliances are in circulation.

No other Barracuda Networks products were affected, the company said.

“Users whose appliances we believe were impacted have been notified via the ESG user interface of actions to take,” the company said. “Barracuda has also reached out to these specific customers.”

The patches went out automatically on May 20 and May 21, Barracuda Networks said.

“We took immediate steps to investigate this vulnerability,” the company said. “Based on our investigation to date, we’ve identified that the vulnerability resulted in unauthorized access to a subset of email gateway appliances.”

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/barracuda-networks-bug-added-to-cisa-vulnerability-list