VYPR
Vendor

Barracudadrive

Products
3
CVEs
28
Across products
28
Status
Private

Products

3

Recent CVEs

28
View all 28 CVEs →
  • CVE-2025-34392CriDec 10, 2025
    risk 0.66cvss 9.8epss 0.25

    Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not verify the URL defined in an attacker-controlled WSDL that is later loaded by the application. This can lead to arbitrary file write and remote code execution via webshell…

  • CVE-2025-34394CriDec 10, 2025
    risk 0.64cvss 9.8epss 0.01

    Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, exposes a .NET Remoting service that is insufficiently protected against deserialization of arbitrary types. This can lead to remote code execution.

  • CVE-2025-34393CriDec 10, 2025
    risk 0.64cvss 9.8epss 0.01

    Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not correctly verify the name of an attacker-controlled WSDL service, leading to insecure reflection. This can result in remote code execution through either invocation of arbitrary…

  • CVE-2023-24078HigFeb 17, 2023
    risk 0.64cvss 8.8epss 0.53

    Real Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the component /FuguHub/cmsdocs/.

  • CVE-2020-23834HigSep 4, 2020
    risk 0.57cvss 8.8epss 0.01

    Insecure Service File Permissions in the bd service in Real Time Logic BarracudaDrive v6.5 allow local attackers to escalate privileges to admin by replacing the %SYSTEMDRIVE%\bd\bd.exe file. When the computer next starts, the new bd.exe will be run as LocalSystem.

  • CVE-2021-42711HigDec 1, 2021
    risk 0.51cvss 7.8epss 0.00

    Barracuda Network Access Client before 5.2.2 creates a Temporary File in a Directory with Insecure Permissions. This file is executed with SYSTEM privileges when an unprivileged user performs a repair operation.

  • CVE-2019-6724HigMar 21, 2019
    risk 0.51cvss 7.8epss 0.01

    The barracudavpn component of the Barracuda VPN Client prior to version 5.0.2.7 for Linux, macOS, and OpenBSD runs as a privileged process and can allow an unprivileged local attacker to load a malicious library, resulting in arbitrary code executing as root.

  • CVE-2025-34395HigDec 10, 2025
    risk 0.49cvss 7.5epss 0.01

    Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, exposes a .NET Remoting service in which an unauthenticated attacker can invoke a method vulnerable to path traversal to read arbitrary files. This vulnerability can be escalated to…

  • CVE-2024-53379HigJan 23, 2025
    risk 0.49cvss 7.5epss 0.00

    Heap buffer overflow in the server site handshake implementation in Real Time Logic LLC's SharkSSL version (from 05/05/24) commit 64808a5e12c83b38f85c943dee0112e428dc2a43 allows a remote attacker to trigger a Denial-of-Service via a malformed Client-Hello message.

  • CVE-2023-26213HigMar 3, 2023
    risk 0.47cvss 7.2epss 0.08

    On Barracuda CloudGen WAN Private Edge Gateway devices before 8 webui-sdwan-1089-8.3.1-174141891, an OS command injection vulnerability exists in /ajax/update_certificate - a crafted HTTP request allows an authenticated attacker to execute arbitrary commands. For example, a name…

  • CVE-2025-65790MedDec 22, 2025
    risk 0.40cvss 6.1epss 0.00

    A reflected cross-site scripting (XSS) vulnerability exists in FuguHub 8.1 when serving SVG files through the /fs/ file manager interface. FuguHub does not sanitize or restrict script execution inside SVG content. When a victim opens a crafted SVG containing an inline …

  • CVE-2018-20369MedDec 23, 2018
    risk 0.40cvss 6.1epss 0.01

    Barracuda Message Archiver 2018 has XSS in the error_msg exception-handling value for the ldap_user parameter to the cgi-mod/ldap_load_entry.cgi module. The injection point of the issue is the Add_Update module.

  • CVE-2014-2526MedMar 25, 2014
    risk 0.40cvss 6.1epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in BarracudaDrive before 6.7 allow remote attackers to inject arbitrary web script or HTML via the (1) sForumName or (2) sDescription parameter to Forum/manage/ForumManager.lsp; (3) sHint, (4) sWord, or (5) nId parameter to…

  • CVE-2024-48075MedNov 12, 2024
    risk 0.27cvss 5.3epss 0.01

    A Heap buffer overflow in the server-site handshake implementation in Real Time Logic SharkSSL from 09/09/24 and earlier allows a remote attacker to trigger a Denial-of-Service via a malformed TLS Client Key Exchange message.

  • CVE-2007-6315Dec 12, 2007
    risk 0.04cvss epss 0.07

    Group Chat in BarracudaDrive Web Server before 3.8 allows remote authenticated users to cause a denial of service (crash) via a HTTP request to /eh/chat.ehintf/C. that does not contain a Connection ID, which results in a NULL pointer dereference.

  • CVE-2007-6314Dec 12, 2007
    risk 0.04cvss epss 0.07

    BarracudaDrive Web Server before 3.8 allows remote attackers to read the source code for web scripts by appending a (1) + (plus), (2) . (dot), or (3) %80 and similar characters to the file name in the URL.

  • CVE-2005-2848Sep 8, 2005
    risk 0.04cvss epss 0.09

    Directory traversal vulnerability in img.pl in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter.

  • CVE-2007-6317Dec 12, 2007
    risk 0.03cvss epss 0.06

    Multiple directory traversal vulnerabilities in BarracudaDrive Web Server before 3.8 allow (1) remote attackers to read arbitrary files via certain ..\ (dot dot backslash) sequences in the URL path, or (2) remote authenticated users to delete arbitrary files or create arbitrary…

  • CVE-2007-6316Dec 12, 2007
    risk 0.03cvss epss 0.04

    Cross-site scripting (XSS) vulnerability in BarracudaDrive Web Server before 3.8 allows remote attackers to inject arbitrary web script or HTML via the URI path in an HTTP GET request, which is activated by administrators viewing log files via the Trace page.

  • CVE-2006-4081Aug 11, 2006
    risk 0.03cvss epss 0.04

    preview_email.cgi in Barracuda Spam Firewall (BSF) 3.3.01.001 through 3.3.03.053 allows remote attackers to execute commands via shell metacharacters ("|" pipe symbol) in the file parameter. NOTE: the attack can be extended to arbitrary commands by the presence of CVE-2006-4000.