CVE-2023-7102

U

se of a Third Party library produced a vulnerability in Barracuda Networks Inc. Barracuda ESG Appliance which allowed Parameter Injection.This issue affected Barracuda ESG Appliance, from 5.1.3.001 through 9.2.1.001, until Barracuda removed the vulnerable logic.

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:barracuda:email_security_gateway_300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:barracuda:email_security_gateway_300:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:barracuda:email_security_gateway_400_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:barracuda:email_security_gateway_400:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:barracuda:email_security_gateway_600_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:barracuda:email_security_gateway_600:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:barracuda:email_security_gateway_800_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:barracuda:email_security_gateway_800:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:barracuda:email_security_gateway_900_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:barracuda:email_security_gateway_900:-:*:*:*:*:*:*:*

History

21 Nov 2024, 08:45

Type Values Removed Values Added
References () https://github.com/haile01/perl_spreadsheet_excel_rce_poc - Third Party Advisory () https://github.com/haile01/perl_spreadsheet_excel_rce_poc - Third Party Advisory
References () https://github.com/jmcnamara/spreadsheet-parseexcel/blob/c7298592e102a375d43150cd002feed806557c15/lib/Spreadsheet/ParseExcel/Utility.pm#L171 - Product () https://github.com/jmcnamara/spreadsheet-parseexcel/blob/c7298592e102a375d43150cd002feed806557c15/lib/Spreadsheet/ParseExcel/Utility.pm#L171 - Product
References () https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2023/MNDT-2023-0019.md - Third Party Advisory () https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2023/MNDT-2023-0019.md - Third Party Advisory
References () https://metacpan.org/dist/Spreadsheet-ParseExcel - Product () https://metacpan.org/dist/Spreadsheet-ParseExcel - Product
References () https://www.barracuda.com/company/legal/esg-vulnerability - Vendor Advisory () https://www.barracuda.com/company/legal/esg-vulnerability - Vendor Advisory
References () https://www.cve.org/CVERecord?id=CVE-2023-7101 - Third Party Advisory () https://www.cve.org/CVERecord?id=CVE-2023-7101 - Third Party Advisory