9.8

CVE-2023-7102

Remote Code Execution (RCE) Vulnerability

Use of a Third Party library produced a vulnerability in Barracuda Networks Inc. Barracuda ESG Appliance which allowed Parameter Injection.This issue affected Barracuda ESG Appliance, from 5.1.3.001 through 9.2.1.001, until Barracuda removed the vulnerable logic.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
BarracudaEmail Security Gateway 300 Firmware Version >= 5.1.3.001 <= 9.2.1.001
BarracudaEmail Security Gateway 400 Firmware Version >= 5.1.3.001 <= 9.2.1.001
BarracudaEmail Security Gateway 600 Firmware Version >= 5.1.3.001 <= 9.2.1.001
BarracudaEmail Security Gateway 800 Firmware Version >= 5.1.3.001 <= 9.2.1.001
BarracudaEmail Security Gateway 900 Firmware Version >= 5.1.3.001 <= 9.2.1.001
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 43.32% 0.986
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-1104 Use of Unmaintained Third Party Components

The product relies on third-party components that are not actively supported or maintained by the original developer or a trusted proxy for the original developer.

https://www.barracuda.com/company/legal/esg-vulnerability
Vendor Advisory
https://github.com/jmcnamara/spreadsheet-parseexcel/blob/c7298592e102a375d43150cd002feed806557c15/lib/Spreadsheet/ParseExcel/Utility.pm#L171
Product
https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2023/MNDT-2023-0019.md
Third Party Advisory
https://github.com/haile01/perl_spreadsheet_excel_rce_poc
Third Party Advisory
https://metacpan.org/dist/Spreadsheet-ParseExcel
Product
https://www.cve.org/CVERecord?id=CVE-2023-7101
Third Party Advisory