CVE Feed

    Dashboard / CVE / CVE-2023-2868

    CVE-2023-2868

    A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.001-9.2.0.006. The vulnerability arises out of a failure to comprehensively sanitize the processing of .tar file (tape archives). The vulnerability stems from incomplete input validation of a user-supplied .tar file as it pertains to the names of the files contained within the archive. As a consequence, a remote attacker can specifically format these file names in a particular manner that will result in remotely executing a system command through Perl's qx operator with the privileges of the Email Security Gateway product. This issue was fixed as part of BNSF-36456 patch. This patch was automatically applied to all customer appliances.

    Published:May 24, 2023
    Last Modified:Oct 24, 2025
    EPS:May 24, 2023
    EPSS Score:0.91367
    CVSS Score:9.4

    CISA Notification

    Description

    A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.001-9.2.0.006. The vulnerability arises out of a failure to comprehensively sanitize the processing of .tar file (tape archives). The vulnerability stems from incomplete input validation of a user-supplied .tar file as it pertains to the names of the files contained within the archive. As a consequence, a remote attacker can specifically format these file names in a particular manner that will result in remotely executing a system command through Perl's qx operator with the privileges of the Email Security Gateway product. This issue was fixed as part of BNSF-36456 patch. This patch was automatically applied to all customer appliances.

    Required Action:

    Apply updates per vendor instructions.

    Notes:

    No extra notes provided.

    Due Date
    Jun 16, 2023
    1183 days ago
    Alert Date
    May 26, 2023
    1204 days ago

    Affected Products

    Vendor
    Barracuda
    Product
    Email Security Gateway 300
    Vendor
    Barracuda
    Product
    Email Security Gateway 300 Firmware
    Vendor
    Barracuda
    Product
    Email Security Gateway 400
    Vendor
    Barracuda
    Product
    Email Security Gateway 400 Firmware
    Vendor
    Barracuda
    Product
    Email Security Gateway 600
    Vendor
    Barracuda
    Product
    Email Security Gateway 600 Firmware
    Vendor
    Barracuda
    Product
    Email Security Gateway 800
    Vendor
    Barracuda
    Product
    Email Security Gateway 800 Firmware
    Vendor
    Barracuda
    Product
    Email Security Gateway 900
    Vendor
    Barracuda
    Product
    Email Security Gateway 900 Firmware

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High