← All CVEs

CVE-2023-7102

critical · 9.8

Use of a Third Party library produced a vulnerability in Barracuda Networks Inc. Barracuda ESG Appliance which allowed Parameter Injection.This issue affected Barracuda ESG Appliance, from 5.1.3.001 through 9.2.1.001, until Barracuda removed the vulnerable logic.

9.8
CVSS
44.6%
EPSS (exploit prob.)
99th
EPSS percentile
2023-12-24
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-1104

Affected products

VendorProductAffected versions
barracudaemail_security_gateway_300_firmware>= 5.1.3.001, <= 9.2.1.001
barracudaemail_security_gateway_300all versions
barracudaemail_security_gateway_400_firmware>= 5.1.3.001, <= 9.2.1.001
barracudaemail_security_gateway_400all versions
barracudaemail_security_gateway_600_firmware>= 5.1.3.001, <= 9.2.1.001
barracudaemail_security_gateway_600all versions
barracudaemail_security_gateway_800_firmware>= 5.1.3.001, <= 9.2.1.001
barracudaemail_security_gateway_800all versions
barracudaemail_security_gateway_900_firmware>= 5.1.3.001, <= 9.2.1.001
barracudaemail_security_gateway_900all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2023-7102