CVE-2023-7102

Use of a Third Party library produced a vulnerability in Barracuda Networks Inc. Barracuda ESG Appliance which allowed Parameter Injection.This issue affected Barracuda ESG Appliance, from 5.1.3.001 through 9.2.1.001, until Barracuda removed the vulnerable logic.

ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
MandiantCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 94%
VendorProductVersion
barracudaemail_security_gateway_300_firmware
5.1.3.001 ≤
𝑥
≤ 9.2.1.001
barracudaemail_security_gateway_400_firmware
5.1.3.001 ≤
𝑥
≤ 9.2.1.001
barracudaemail_security_gateway_600_firmware
5.1.3.001 ≤
𝑥
≤ 9.2.1.001
barracudaemail_security_gateway_800_firmware
5.1.3.001 ≤
𝑥
≤ 9.2.1.001
barracudaemail_security_gateway_900_firmware
5.1.3.001 ≤
𝑥
≤ 9.2.1.001
𝑥
= Vulnerable software versions