VYPR

Email Security Gateway 300 Firmware

by Barracuda Networks

CVEs (2)

  • CVE-2023-2868CriKEVMay 24, 2023
    risk 0.83cvss 9.4epss 0.87

    A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.001-9.2.0.006. The vulnerability arises out of a failure to comprehensively sanitize the processing of .tar file (tape…

  • CVE-2023-7102CriDec 24, 2023
    risk 0.70cvss 9.8epss 0.44

    Use of a Third Party library produced a vulnerability in Barracuda Networks Inc. Barracuda ESG Appliance which allowed Parameter Injection.This issue affected Barracuda ESG Appliance, from 5.1.3.001 through 9.2.1.001, until Barracuda removed the vulnerable logic.