ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

Barracuda Zero

criticalExploit / PoCimportance 60CVE-2023-2868

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-2868
Unauthenticated Command Injection in Barracuda Email Security Gateway Appliances via .tar Files

CVE-2023-2868 is a critical (CVSS 9.8) remote command injection vulnerability in the Barracuda Email Security Gateway (ESG) appliance form factor (models 300, 400, 600, 800 and 900), caused by incomplete input validation of user-supplied .tar archives, specifically the names of the files contained within them. An attacker can deliver a specially crafted .tar file whose internal file names are formatted so that, when the ESG processes the archive, commands are executed through Perl's qx operator. Successful exploitation yields remote command execution with the privileges of the ESG product, and in the observed campaign attackers deployed a backdoor (reported as "SUBMARINE") and persisted on compromised appliances. Only customers running ESG appliances on versions 5.1.3.001 through 9.2.0.006 are affected. Exploitation is confirmed in the wild — CISA added it to the KEV on 2023-05-26, EPSS puts 30-day exploitation probability at 87.7%, and public reporting attributes active exploitation to a Chinese-nexus espionage group (associated in headlines with Salt Typhoon) targeting government, military, and telecom victims; Barracuda's BNSF-36456 patch was applied automatically to customer appliances.

Do: Verify that each ESG appliance received the automatic BNSF-36456 patch (running fixed firmware at or above 9.2.0.006's successor per vendor instructions), and check appliances for indicators of compromise, including unauthorized command activity and the "SUBMARINE" backdoor, using Barracuda's IOC guidance. Because the espionage campaign established persistence, Barracuda urged full replacement rather than patching of compromised appliances; replace any ESG showing signs of compromise and review email logs for malicious .tar attachments. Limit or monitor internet exposure of ESG management interfaces while remediation proceeds.

9.888% KEV
  • Barracuda Networks Email Security Gateway (ESG) 300 firmware (appliance form factor) 5.1.3.001 – 9.2.0.006
  • Barracuda Networks Email Security Gateway (ESG) 400 firmware (appliance form factor) 5.1.3.001 – 9.2.0.006
  • Barracuda Networks Email Security Gateway (ESG) 600 firmware (appliance form factor) 5.1.3.001 – 9.2.0.006
  • +2 more
largetens of thousands of deployed ESG appliances (public scans show Barracuda ESGs among commonly internet-exposed email security devices); Barracuda's incident…
Full article395 words · extracted from infosecurity-magazine.com · click to collapse

A zero-day vulnerability in the Barracuda Email Security Gateway (ESG) discovered in late May was exploited in a Chinese espionage campaign from October 2022, according to Mandiant.

The Google-owned threat intelligence firm revealed in a new report yesterday that new threat actor UNC4841 began sending phishing emails as far back as October 10 last year.

These malicious emails contained file attachments designed to exploit the Barracuda bug CVE-2023-2868 to gain initial access to vulnerable appliances, it added.

Read more on Chinese APT activity: Cyber Warfare Escalates Amid China-Taiwan Tensions.

Once a foothold has been established, the group used Saltwater, Seaside and Seaspray malware to maintain a presence on the devices by masquerading as legitimate Barracuda ESG modules or services.

“Post initial compromise, Mandiant and Barracuda observed UNC4841 aggressively target specific data of interest for exfiltration, and in some cases, leverage access to an ESG appliance to conduct lateral movement into the victim network, or to send mail to other victim appliances,” it continued.

“Mandiant has also observed UNC4841 deploy additional tooling to maintain presence on ESG appliances.”

Barracuda discovered the campaign on May 19 and released patches to contain and remediate the threat two days later. However, the threat group switched malware and deployed new persistence mechanisms to maintain access, Mandiant explained.

Between May 22 and 24, UNC4841 targeted victims in 16 countries with “high frequency” operations, prompting Barracuda to take the unusual step of urging customers to isolate and replace their appliances, whatever their patch status.

The security vendor was praised for its rapid response and sharing of product-specific expertise that enabled a fully-fledged investigation.

However, the threat from UNC4841 persists.

“UNC4841 has shown to be highly responsive to defensive efforts and actively modifies TTPs to maintain their operations. Mandiant strongly recommends impacted Barracuda customers continue to hunt for this actor and investigate affected networks,” Mandiant concluded.

“We expect UNC4841 will continue to alter their TTPs and modify their toolkit, especially as network defenders continue to take action against this adversary and their activity is further exposed by the infosec community.”

The threat actor is assessed to be an espionage actor working to support the Chinese government. A third of its victims were government agencies, although individual targets included well-known academics in Taiwan and Hong Kong, and Asian and European government officials in South East Asia.

Editorial image credit: Ken Wolter / Shutterstock.com

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/barracuda-zero-day-exploited/