Barracuda Networks Grapples with Two Zero-Day Vulnerabilities in ESG Devices

The Barracuda security team, in collaboration with Mandiant, investigated the first Barracuda ESG vulnerability, CVE-2023-7102.

Barracuda Networks recently encountered a challenge as it uncovered two zero-day vulnerabilities, specifically CVE-2023-7102 and CVE-2023-7101. These Barracuda vulnerabilities were intricately linked to the Spreadsheet::ParseExcel library, revealing an Arbitrary Code Execution (ACE) flaw in the third-party library. 

Exploited by the China Nexus actor UNC4841, these security flaws posed a serious threat by targeting Barracuda Email Security Gateway Appliance (ESG) devices through malicious Excel email attachments.

Decoding Barracuda Vulnerabilities

The Barracuda security team, in collaboration with Mandiant, investigated the first Barracuda ESG vulnerability, CVE-2023-7102. This flaw allowed threat actors to execute arbitrary code within the ESG appliance’s third-party library, Spreadsheet::ParseExcel.

This open-source library, integral to the Amavis virus scanner within the ESG appliance, became the focal point of the attack, facilitating the deployment of specially crafted Excel email attachments to compromise a limited number of ESG devices.

Attributing the malicious activity to UNC4841, a China-associated threat actor, Barracuda underscored the severity of the vulnerability with a CVSSv2 score of 7.5 and a CVSS3 score of 8.8. This security flaw impacted Barracuda ESG appliances within the version range from 5.1.3.001 to 9.2.1.001.

Barracuda’s Swift Response to ESG Vulnerabilities

In response to the threat, Barracuda took proactive measures by deploying a security update on December 21, 2023, to all active ESGs.

This update effectively addressed the ACE vulnerability in Spreadsheet::ParseExcel, showcasing Barracuda’s commitment to fortifying its technology and safeguarding users without requiring customer intervention.

Moreover, Barracuda reported active attacks targeting CVE-2023-7102, further implicating UNC4841, a group known for exploiting vulnerabilities such as CVE-2023-2868. The swift deployment of security updates highlighted Barracuda’s dedication to staying ahead of state-sponsored threats

Subsequently, Barracuda identified new variants of SEASPY and SALTWATER malware on compromised ESG devices. Responding decisively, on December 22, 2023, Barracuda deployed a patch to remediate compromised ESG devices exhibiting signs of compromise related to these newly identified malware variants.

The discovery and rapid mitigation of the Barracuda ESG vulnerability (CVE-2023-7102) emphasizes the importance of proactive cybersecurity measures and accountability against online threats and actors exploiting critical vulnerabilities in devices and networks. 

Media Disclaimer: This report is based on internal and external research obtained through various means. The information provided is for reference purposes only, and users bear full responsibility for their reliance on it. The Cyber Express assumes no liability for the accuracy or consequences of using this information.

Ashish Khaitan

Ashish is a technical writer at The Cyber Express. He adores writing about the latest technologies and covering the latest cybersecurity events. In his free time, he likes to play horror and open-world video games.

Recent Posts

New Zealand Targets Russian Cyber Actors With Fresh Sanctions

New Zealand has now imposed sanctions on more than 2,000 Russian individuals, entities and vessels, alongside trade restrictions. T

4 hours ago

Suisun City Declares Emergency After Cyberattack Disrupts Systems

Suisun City Emergency follows a cyberattack that shut down the city’s IT network, disrupting police, fire and 911 communications.

1 day ago

AI Agent Exploits Gym System Vulnerability, Cancels Waitlist Booking in Australia

An AI agent exploited a gym system vulnerability in Australia, booked classes months ahead and cancelled another user's reservation.

1 day ago

Ransomware Kingpin Gets 16 Years for Global Cyberattacks

The Justice Department’s Office of International Affairs provided substantial assistance with Silnikau’s extradition and the collection of evidence.

1 day ago

Levi Strauss Hit by Cyberattack, Corporate Files Accessed

The Levi Strauss cyberattack comes as several major retailers have reported cybersecurity incidents involving their own systems or third-party service…

1 day ago

The Cyber Express Weekly Roundup: Ransomware Surge, Government Data Breaches, Logistics Disruptions, and Third-Party Security Risks

This week's roundup covers Qilin ransomware, government database breaches, and third-party cyberattacks reshaping today's threat landscape.

4 days ago

This website uses cookies. By continuing to use this website you are giving consent to cookies being used.

Read More