Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Jun 16, 2023

CVE-2023-2868

High
EPSS 89.5%CISA KEV
Barracuda Networks/Email Security Gateway (ESG) Appliance

Description

Barracuda Email Security Gateway (ESG) appliance contains an improper input validation vulnerability of a user-supplied .tar file, leading to remote command injection.

EPSS — Exploit Probability

89.5%

Higher than 99.5% of all CVEs

Required Action

https://status.barracuda.com/incidents/34kx82j5n4q9; https://nvd.nist.gov/vuln/detail/CVE-2023-2868

Risk Assessment

HIGH
In CISA KEV
High EPSS

Details

Severity
High
EPSS
89.5%
CISA KEV
Yes
Ransomware
Unknown
Articles
0

Timeline

Published

May 26, 2023

Added to KEV

May 26, 2023

Remediation Due

Jun 16, 2023

Affected Product

Barracuda Networks

Email Security Gateway (ESG) Appliance

View all Barracuda Networks CVEs