CVE Feed

    Dashboard / CVE / CVE-2010-20109

    CVE-2010-20109

    Barracuda products, confirmed in Spam & Virus Firewall, SSL VPN, and Web Application Firewall versions prior to October 2010, contain a path traversal vulnerability in the view_help.cgi endpoint. The locale parameter fails to properly sanitize user input, allowing attackers to inject traversal sequences and null-byte terminators to access arbitrary files on the underlying system. By exploiting this flaw, unauthenticated remote attackers can retrieve sensitive configuration files such as /mail/snapshot/config.snapshot, potentially exposing credentials, internal settings, and other critical data.

    Published:Aug 21, 2025
    Last Modified:Apr 15, 2026
    EPS:Aug 21, 2025
    EPSS Score:0.51192
    CVSS Score:8.7

    Affected Products

    Vendor
    Barracuda
    Product
    Vpn Client
    Vendor
    Barracuda
    Product
    Web Application Firewall
    Vendor
    Barracudanetworks
    Product
    Barracuda Ssl Vpn
    Vendor
    Barracudanetworks
    Product
    Spam & Virus Firewall 600

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High