Remote Code Execution (RCE) Vulnerability
Published Dec 24, 2023
9.8
CRITICALCVSS 3.1
EPSS 44.57%
Description
Use of a Third Party library produced a vulnerability in Barracuda Networks Inc. Barracuda ESG Appliance which allowed Parameter Injection.This issue affected Barracuda ESG Appliance, from 5.1.3.001 through 9.2.1.001, until Barracuda removed the vulnerable logic.
Affected products
-
Affected
- ≥ 5.1.3.001, ≤ 9.2.1.001
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Barracuda Networks Inc. | Barracuda ESG Appliance | unaffected | Affected
|
Configuration 1
- ≥ 5.1.3.001 · ≤ 9.2.1.001
Running on/with
- n/a
Configuration 2
- ≥ 5.1.3.001 · ≤ 9.2.1.001
Running on/with
- n/a
Configuration 3
- ≥ 5.1.3.001 · ≤ 9.2.1.001
Running on/with
- n/a
Configuration 4
- ≥ 5.1.3.001 · ≤ 9.2.1.001
Running on/with
- n/a
Configuration 5
- ≥ 5.1.3.001 · ≤ 9.2.1.001
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-59286 Advisory
- https://github.com/haile01/perl_spreadsheet_excel_rce_poc Third Party Advisory
- https://github.com/jmcnamara/spreadsheet-parseexcel/blob/c7298592e102a375d43150cd002feed806557c15/lib/Spreadsheet/ParseExcel/Utility.pm#L171 Product
- https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2023/MNDT-2023-0019.md Third Party Advisory
- https://metacpan.org/dist/Spreadsheet-ParseExcel Product
- https://www.barracuda.com/company/legal/esg-vulnerability Vendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2023-7101 Third Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-59286 | Advisory | |
| https://github.com/haile01/perl_spreadsheet_excel_rce_poc | Third Party Advisory | |
| https://github.com/jmcnamara/spreadsheet-parseexcel/blob/c7298592e102a375d43150cd002feed806557c15/lib/Spreadsheet/ParseExcel/Utility.pm#L171 | Product | |
| https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2023/MNDT-2023-0019.md | Third Party Advisory | |
| https://metacpan.org/dist/Spreadsheet-ParseExcel | Product | |
| https://www.barracuda.com/company/legal/esg-vulnerability | Vendor Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2023-7101 | Third Party Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data