ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Attackers hacked Barracuda ESG appliances via zero-day since October 2022

criticalExploit / PoCimportance 60CVE-2023-2868

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-2868
Unauthenticated Command Injection in Barracuda Email Security Gateway Appliances via .tar Files

CVE-2023-2868 is a critical (CVSS 9.8) remote command injection vulnerability in the Barracuda Email Security Gateway (ESG) appliance form factor (models 300, 400, 600, 800 and 900), caused by incomplete input validation of user-supplied .tar archives, specifically the names of the files contained within them. An attacker can deliver a specially crafted .tar file whose internal file names are formatted so that, when the ESG processes the archive, commands are executed through Perl's qx operator. Successful exploitation yields remote command execution with the privileges of the ESG product, and in the observed campaign attackers deployed a backdoor (reported as "SUBMARINE") and persisted on compromised appliances. Only customers running ESG appliances on versions 5.1.3.001 through 9.2.0.006 are affected. Exploitation is confirmed in the wild — CISA added it to the KEV on 2023-05-26, EPSS puts 30-day exploitation probability at 87.7%, and public reporting attributes active exploitation to a Chinese-nexus espionage group (associated in headlines with Salt Typhoon) targeting government, military, and telecom victims; Barracuda's BNSF-36456 patch was applied automatically to customer appliances.

Do: Verify that each ESG appliance received the automatic BNSF-36456 patch (running fixed firmware at or above 9.2.0.006's successor per vendor instructions), and check appliances for indicators of compromise, including unauthorized command activity and the "SUBMARINE" backdoor, using Barracuda's IOC guidance. Because the espionage campaign established persistence, Barracuda urged full replacement rather than patching of compromised appliances; replace any ESG showing signs of compromise and review email logs for malicious .tar attachments. Limit or monitor internet exposure of ESG management interfaces while remediation proceeds.

9.888% KEV
  • Barracuda Networks Email Security Gateway (ESG) 300 firmware (appliance form factor) 5.1.3.001 – 9.2.0.006
  • Barracuda Networks Email Security Gateway (ESG) 400 firmware (appliance form factor) 5.1.3.001 – 9.2.0.006
  • Barracuda Networks Email Security Gateway (ESG) 600 firmware (appliance form factor) 5.1.3.001 – 9.2.0.006
  • +2 more
largetens of thousands of deployed ESG appliances (public scans show Barracuda ESGs among commonly internet-exposed email security devices); Barracuda's incident…

Indicators of compromiseAll →

TypeIndicatorContext
email[email protected]nce after receiving notice in your UI, contact support now ([email protected]),” they advise .
Full article450 words · extracted from helpnetsecurity.com · click to collapse

Barracuda says that the recently discovered compromise of some of it clients’ ESG appliances via a zero-day vulnerability (CVE-2023-2868) resulted in the deployment of three types of malware and data exfiltration.

Barracuda ESG zero-day

The company did not say how many organizations have been breached, but has comfirmed that the “earliest identified evidence of exploitation of CVE-2023-2868 is currently October 2022.”

Zero-day exploited, Barracuda ESG appliances backdoored

On May 23, Barracuda Networks publicly acknowledged that attackers have been exploiting CVE-2023-2868 to breach Email Security Gateway on-prem physical appliances at various organizations.

Today, they confirmed that the first patch, which remediated the remote command injection vulnerability, was applied to all ESG appliances worldwide on May 20, and was followed by a script that was “deployed to all impacted appliances to contain the incident and counter unauthorized access methods.”

With the help of cyber security experts from Mandiant, they found that at least three different malicious payloads had been dropped on affected appliances:

  • SALTWATER, a trojanized module for the Barracuda SMTP daemon (bsmtpd), which serves as a backdoor that has proxy and tunneling capabilities and allows attackers to upload or download arbitrary files and execute commands.
  • SEASPY, an x64 ELF persistence backdoor that poses as a legitimate Barracuda Networks service and establishes itself as a PCAP filter, specifically monitoring traffic on port 25 (SMTP)
  • SEASIDE, a Lua-based module for the Barracuda SMTP daemon (bsmtpd) that establishes a connection to the attackers’ C2 server and helps establish a reverse shell (to provide access to the system)

There is some code overlap between SEASPY and cd00r, a publicly available PoC backdoor, the company said, but the malware has yet to be tied to specific threat actors.

Advice for impacted customers

Barracuda’s advice to impacted ESG customers – who have also been privately alerted – is as follows:

  • Ensure that the appliance is receiving and applying updates and security patches from Barracuda
  • If possible, remove the compromised ESG appliance and contact the company to obtain a new ESG virtual or hardware appliance
  • Rotate any credentials connected to the ESG appliance
  • Review network logs and search for IOCs and IPs shared by the company

Barracuda has also provided YARA rules to help organizations hunt for the malicious TAR file that exploits CVE-2023-2868.

“A series of security patches are being deployed to all appliances in furtherance of our containment strategy,” the company added, but did not elaborate further.

UPDATE (June 8, 2023, 08:20 a.m. ET):

Barracuda has issued an action notice on Tuesday, saying that impacted ESG appliances should be immediately replaced regardless of patch version level.

“If you have not replaced your appliance after receiving notice in your UI, contact support now ([email protected]),” they advise.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2023/05/30/barracuda-esg-zero-day/