Barracuda Urges Swift Replacement of Vulnerable ESG Appliances
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-2868 | Unauthenticated Command Injection in Barracuda Email Security Gateway Appliances via .tar Files CVE-2023-2868 is a critical (CVSS 9.8) remote command injection vulnerability in the Barracuda Email Security Gateway (ESG) appliance form factor (models 300, 400, 600, 800 and 900), caused by incomplete input validation of user-supplied .tar archives, specifically the names of the files contained within them. An attacker can deliver a specially crafted .tar file whose internal file names are formatted so that, when the ESG processes the archive, commands are executed through Perl's qx operator. Successful exploitation yields remote command execution with the privileges of the ESG product, and in the observed campaign attackers deployed a backdoor (reported as "SUBMARINE") and persisted on compromised appliances. Only customers running ESG appliances on versions 5.1.3.001 through 9.2.0.006 are affected. Exploitation is confirmed in the wild — CISA added it to the KEV on 2023-05-26, EPSS puts 30-day exploitation probability at 87.7%, and public reporting attributes active exploitation to a Chinese-nexus espionage group (associated in headlines with Salt Typhoon) targeting government, military, and telecom victims; Barracuda's BNSF-36456 patch was applied automatically to customer appliances. Do: Verify that each ESG appliance received the automatic BNSF-36456 patch (running fixed firmware at or above 9.2.0.006's successor per vendor instructions), and check appliances for indicators of compromise, including unauthorized command activity and the "SUBMARINE" backdoor, using Barracuda's IOC guidance. Because the espionage campaign established persistence, Barracuda urged full replacement rather than patching of compromised appliances; replace any ESG showing signs of compromise and review email logs for malicious .tar attachments. Limit or monitor internet exposure of ESG management interfaces while remediation proceeds. | 9.8 | 88% | KEV |
| largetens of thousands of deployed ESG appliances (public scans show Barracuda ESGs among commonly internet-exposed email security devices); Barracuda's incident… |
Full article328 words · extracted from infosecurity-magazine.com · click to collapse

Enterprise-grade security solution provider Barracuda has urged customers to replace Email Security Gateway (ESG) regardless of patch version level.
This follows attacks observed targeting a now-patched zero-day vulnerability. The flaw (tracked CVE-2023-2868) was exploited as early as October 2022 and patched remotely back on May 20, 2023. The attackers' access to the compromised appliances was reportedly cut off one day later by deploying a dedicated script.
According to Barracuda's original advisory, published on June 1, the vulnerability that was discovered exists within a module responsible for screening email attachments. This was updated on June 6 to encourage the replacement of the ESG.
Read more on email-focused attacks: Microsoft Warns of Increase in Business Email Compromise Attacks
The firm determined that the flaw was exploited to gain unauthorized access to a specific subset of ESG appliances. Malware was then found on a portion of these appliances, allowing for persistent backdoor access. Evidence of data exfiltration has also been discovered on some affected devices.
Incident response teams from security firm Rapid7 are also investigating the ESG exploitation bug and have published a blog post on the findings on Thursday.
"The pivot from patch to total replacement of affected devices is fairly stunning and implies the malware the threat actors deployed somehow achieves persistence at a low enough level that even wiping the device wouldn't eradicate attacker access," reads the Rapid7 advisory.
According to insights shared by John Bambenek, principal threat hunter at Netenrich, customers dealing with virtual appliances will have an easier time. In such cases, the solution is relatively simple—provisioning and configuring a new virtual appliance and removing the old one.
"Those using hardware appliances will have a difficult road ahead of them as they need to get a new device to replace it with," Bambenek added.
The Barracuda updates on CVE-2023-2868 come a few months after Quarks Lab revealed that two previously discovered TPM 2.0 library vulnerabilities could have affected billions of Internet of Things (IoT) devices.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/barracuda-replacement-esg/