Skip to content
Noroxi

Barracuda records

18 published records for vendor barracuda.

All records

18 records
  • Remote Code injection in Barracuda Email Security Gateway

    CriticalCVSS 9.8KEVWeaponizedEPSS 88%

    barracuda · email security gateway 300 firmwareMay 24, 2023

  • Remote Code Execution (RCE) Vulnerability

    CriticalCVSS 9.8WeaponizedEPSS 45%

    barracuda · email security gateway 300 firmwareDec 24, 2023

  • Barracuda RMM < 2025.1.1 Service Center Absolute Path Traversal RCE

    CriticalCVSS 10.0No exploitEPSS 25%

    barracuda · rmmDec 10, 2025

  • Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a permanent authentication

    CriticalCVSS 9.8Proof of conceptEPSS 17%

    barracuda · web application firewallFeb 11, 2020

  • Privilege escalation vulnerability in Barracuda Load Balancer 5.0.0.015 via the use of an improperly protected SSH key.

    CriticalCVSS 9.8No exploitEPSS 2%

    barracuda · load balancerAug 28, 2017

  • Hard coded weak credentials in Barracuda Load Balancer 5.0.0.015.

    CriticalCVSS 9.8No exploitEPSS 2%

    barracuda · load balancerAug 28, 2017

  • Barracuda RMM < 2025.1.1 Service Center Insecure Reflection RCE

    CriticalCVSS 10.0No exploitEPSS 1%

    barracuda · rmmDec 10, 2025

  • Barracuda RMM < 2025.1.1 Service Center .NET Remoting Deserialization RCE

    CriticalCVSS 10.0No exploitEPSS 1%

    barracuda · rmmDec 10, 2025

  • CVE-2017-6320
    38Monitor

    A remote command injection vulnerability exists in the Barracuda Load Balancer product line (confirmed on v5.4.0.004 (2015-11-26) and v6.0.1

    HighCVSS 8.8Proof of conceptEPSS 11%

    barracuda · load balancer adcJul 18, 2017

  • Barracuda RMM < 2025.1.1 Service Center .NET Remoting Path Traversal RCE

    HighCVSS 8.7No exploitEPSS 1%

    barracuda · rmmDec 10, 2025

  • CVE-2019-6724
    31Monitor

    The barracudavpn component of the Barracuda VPN Client prior to version 5.0.2.7 for Linux, macOS, and OpenBSD runs as a privileged process a

    HighCVSS 7.8No exploitEPSS 1%

    barracuda · vpn clientMar 21, 2019

  • Barracuda Network Access Client before 5.2.2 creates a Temporary File in a Directory with Insecure Permissions.

    HighCVSS 7.8No exploitEPSS 0%

    barracuda · network access clientDec 1, 2021

  • On Barracuda CloudGen WAN Private Edge Gateway devices before 8 webui-sdwan-1089-8.3.1-174141891, an OS command injection vulnerability exis

    HighCVSS 7.2No exploitEPSS 8%

    barracuda · t100b firmwareMar 3, 2023

  • CVE-2019-5648
    26Monitor

    LDAP Credential Exposure in Barracuda Load Balancer ADC

    MediumCVSS 6.5No exploitEPSS 1%

    barracuda · load balancer adc firmwareMar 12, 2020

  • Barracuda Message Archiver 2018 has XSS in the error_msg exception-handling value for the ldap_user parameter to the cgi-mod/ldap_load_entry

    MediumCVSS 6.1No exploitEPSS 1%

    barracuda · message archiverDec 22, 2018

  • CVE-2025-8319
    24Monitor

    the BMA login interface allows arbitrary JavaScript or HTML to be written straight into the page’s Document Object Model via the error= URL

    MediumCVSS 6.1No exploitEPSS 0%

    barracuda · message archiver firmwareJul 29, 2025

  • CVE-2015-0962
    17Monitor

    Barracuda Web Filter 7.x and 8.x before 8.1.0.005, when SSL Inspection is enabled, uses the same root Certification Authority certificate ac

    MediumCVSS 4.3No exploitEPSS 1%

    barracuda · web filterMay 25, 2015

  • CVE-2015-0961
    17Monitor

    Barracuda Web Filter before 8.1.0.005, when SSL Inspection is enabled, does not verify X.509 certificates from upstream SSL servers, which a

    MediumCVSS 4.3No exploitEPSS 1%

    barracuda · web filterMay 25, 2015