CVE-2023-7102
Use of a Third Party library produced a vulnerability in Barracuda Networks Inc. Barracuda ESG Appliance which allowed Parameter Injection.This issue affected Barracuda ESG Appliance, from 5.1.3.001 through 9.2.1.001, until Barracuda removed the vulnerable logic.
- Affected products
- Barracuda Esg Appliance, Office Excel
- Barracuda Email Security Gateway 300 Firmware
- β€ 9.2.1.001
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 43.6% (99th percentile)
- Weakness
- CWE-1104
- NVD status
- Modified
- Published
- 2023-12-24
- Attack patterns
- CAPEC-137
CVE-2023-7102 at NVD
2 known exploits for CVE-2023-7102
Proof-of-concept code and exploit modules indexed by Sploitus