Записи Barracuda
18 опубликованных записей вендора barracuda.
Профиль для исследователя
- Попали в KEV
- 1 · 5,6 %
- С эксплойтом
- 2 · 11,1 %
- Pre-auth RCE
- 6
- С записью об исправлении
- 11,1 %
- Медиана: публикация → KEV
- 2 дн.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-20 Improper Input Validation1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-276 Incorrect Default Permissions1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
18 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
95Срочно | CVE-2023-2868Готовый эксплойт | Remote Code injection in Barracuda Email Security Gatewaybarracuda · email security gateway 300 firmware · CWE-20 | Критическая9,8 | KEV | 87,7 % | 24 мая 2023 г. |
52В плане | CVE-2023-7102Готовый эксплойт | Remote Code Execution (RCE) Vulnerabilitybarracuda · email security gateway 300 firmware · CWE-1104 | Критическая9,8 | — | 44,6 % | 24 дек. 2023 г. |
47В плане | CVE-2025-34392Эксплойта нет | Barracuda RMM < 2025.1.1 Service Center Absolute Path Traversal RCEbarracuda · rmm · CWE-36 | Критическая10,0 | — | 24,7 % | 10 дек. 2025 г. |
44В плане | CVE-2014-2595Proof of concept | Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a permanent authenticationbarracuda · web application firewall · CWE-613 | Критическая9,8 | — | 16,9 % | 11 февр. 2020 г. |
40В плане | CVE-2014-8428Эксплойта нет | Privilege escalation vulnerability in Barracuda Load Balancer 5.0.0.015 via the use of an improperly protected SSH key.barracuda · load balancer · CWE-264 | Критическая9,8 | — | 2,4 % | 28 авг. 2017 г. |
40В плане | CVE-2014-8426Эксплойта нет | Hard coded weak credentials in Barracuda Load Balancer 5.0.0.015.barracuda · load balancer · CWE-798 | Критическая9,8 | — | 2,2 % | 28 авг. 2017 г. |
40В плане | CVE-2025-34393Эксплойта нет | Barracuda RMM < 2025.1.1 Service Center Insecure Reflection RCEbarracuda · rmm · CWE-470 | Критическая10,0 | — | 0,7 % | 10 дек. 2025 г. |
40В плане | CVE-2025-34394Эксплойта нет | Barracuda RMM < 2025.1.1 Service Center .NET Remoting Deserialization RCEbarracuda · rmm · CWE-502 | Критическая10,0 | — | 0,7 % | 10 дек. 2025 г. |
38Наблюдать | CVE-2017-6320Proof of concept | A remote command injection vulnerability exists in the Barracuda Load Balancer product line (confirmed on v5.4.0.004 (2015-11-26) and v6.0.1barracuda · load balancer adc · CWE-78 | Высокая8,8 | — | 11,1 % | 18 июл. 2017 г. |
34Наблюдать | CVE-2025-34395Эксплойта нет | Barracuda RMM < 2025.1.1 Service Center .NET Remoting Path Traversal RCEbarracuda · rmm · CWE-22 | Высокая8,7 | — | 0,8 % | 10 дек. 2025 г. |
31Наблюдать | CVE-2019-6724Эксплойта нет | The barracudavpn component of the Barracuda VPN Client prior to version 5.0.2.7 for Linux, macOS, and OpenBSD runs as a privileged process abarracuda · vpn client · CWE-426 | Высокая7,8 | — | 0,5 % | 21 мар. 2019 г. |
31Наблюдать | CVE-2021-42711Эксплойта нет | Barracuda Network Access Client before 5.2.2 creates a Temporary File in a Directory with Insecure Permissions.barracuda · network access client · CWE-276 | Высокая7,8 | — | 0,3 % | 1 дек. 2021 г. |
30Наблюдать | CVE-2023-26213Эксплойта нет | On Barracuda CloudGen WAN Private Edge Gateway devices before 8 webui-sdwan-1089-8.3.1-174141891, an OS command injection vulnerability exisbarracuda · t100b firmware · CWE-78 | Высокая7,2 | — | 7,9 % | 3 мар. 2023 г. |
26Наблюдать | CVE-2019-5648Эксплойта нет | LDAP Credential Exposure in Barracuda Load Balancer ADCbarracuda · load balancer adc firmware · CWE-522 | Средняя6,5 | — | 1,1 % | 12 мар. 2020 г. |
24Наблюдать | CVE-2018-20369Эксплойта нет | Barracuda Message Archiver 2018 has XSS in the error_msg exception-handling value for the ldap_user parameter to the cgi-mod/ldap_load_entrybarracuda · message archiver · CWE-79 | Средняя6,1 | — | 0,7 % | 22 дек. 2018 г. |
24Наблюдать | CVE-2025-8319Эксплойта нет | the BMA login interface allows arbitrary JavaScript or HTML to be written straight into the page’s Document Object Model via the error= URL barracuda · message archiver firmware · CWE-79 | Средняя6,1 | — | 0,2 % | 29 июл. 2025 г. |
17Наблюдать | CVE-2015-0962Эксплойта нет | Barracuda Web Filter 7.x and 8.x before 8.1.0.005, when SSL Inspection is enabled, uses the same root Certification Authority certificate acbarracuda · web filter · CWE-18 | Средняя4,3 | — | 1,4 % | 25 мая 2015 г. |
17Наблюдать | CVE-2015-0961Эксплойта нет | Barracuda Web Filter before 8.1.0.005, when SSL Inspection is enabled, does not verify X.509 certificates from upstream SSL servers, which abarracuda · web filter | Средняя4,3 | — | 0,8 % | 25 мая 2015 г. |
- CVE-2023-286895Срочно
Remote Code injection in Barracuda Email Security Gateway
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 88 %barracuda · email security gateway 300 firmware24 мая 2023 г.
- CVE-2023-710252В плане
Remote Code Execution (RCE) Vulnerability
КритическаяCVSS 9,8Готовый эксплойтEPSS 45 %barracuda · email security gateway 300 firmware24 дек. 2023 г.
- CVE-2025-3439247В плане
Barracuda RMM < 2025.1.1 Service Center Absolute Path Traversal RCE
КритическаяCVSS 10,0Эксплойта нетEPSS 25 %barracuda · rmm10 дек. 2025 г.
- CVE-2014-259544В плане
Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a permanent authentication
КритическаяCVSS 9,8Proof of conceptEPSS 17 %barracuda · web application firewall11 февр. 2020 г.
- CVE-2014-842840В плане
Privilege escalation vulnerability in Barracuda Load Balancer 5.0.0.015 via the use of an improperly protected SSH key.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %barracuda · load balancer28 авг. 2017 г.
- CVE-2014-842640В плане
Hard coded weak credentials in Barracuda Load Balancer 5.0.0.015.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %barracuda · load balancer28 авг. 2017 г.
- CVE-2025-3439340В плане
Barracuda RMM < 2025.1.1 Service Center Insecure Reflection RCE
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %barracuda · rmm10 дек. 2025 г.
- CVE-2025-3439440В плане
Barracuda RMM < 2025.1.1 Service Center .NET Remoting Deserialization RCE
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %barracuda · rmm10 дек. 2025 г.
- CVE-2017-632038Наблюдать
A remote command injection vulnerability exists in the Barracuda Load Balancer product line (confirmed on v5.4.0.004 (2015-11-26) and v6.0.1
ВысокаяCVSS 8,8Proof of conceptEPSS 11 %barracuda · load balancer adc18 июл. 2017 г.
- CVE-2025-3439534Наблюдать
Barracuda RMM < 2025.1.1 Service Center .NET Remoting Path Traversal RCE
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %barracuda · rmm10 дек. 2025 г.
- CVE-2019-672431Наблюдать
The barracudavpn component of the Barracuda VPN Client prior to version 5.0.2.7 for Linux, macOS, and OpenBSD runs as a privileged process a
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %barracuda · vpn client21 мар. 2019 г.
- CVE-2021-4271131Наблюдать
Barracuda Network Access Client before 5.2.2 creates a Temporary File in a Directory with Insecure Permissions.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %barracuda · network access client1 дек. 2021 г.
- CVE-2023-2621330Наблюдать
On Barracuda CloudGen WAN Private Edge Gateway devices before 8 webui-sdwan-1089-8.3.1-174141891, an OS command injection vulnerability exis
ВысокаяCVSS 7,2Эксплойта нетEPSS 8 %barracuda · t100b firmware3 мар. 2023 г.
- CVE-2019-564826Наблюдать
LDAP Credential Exposure in Barracuda Load Balancer ADC
СредняяCVSS 6,5Эксплойта нетEPSS 1 %barracuda · load balancer adc firmware12 мар. 2020 г.
- CVE-2018-2036924Наблюдать
Barracuda Message Archiver 2018 has XSS in the error_msg exception-handling value for the ldap_user parameter to the cgi-mod/ldap_load_entry
СредняяCVSS 6,1Эксплойта нетEPSS 1 %barracuda · message archiver22 дек. 2018 г.
- CVE-2025-831924Наблюдать
the BMA login interface allows arbitrary JavaScript or HTML to be written straight into the page’s Document Object Model via the error= URL
СредняяCVSS 6,1Эксплойта нетEPSS 0 %barracuda · message archiver firmware29 июл. 2025 г.
- CVE-2015-096217Наблюдать
Barracuda Web Filter 7.x and 8.x before 8.1.0.005, when SSL Inspection is enabled, uses the same root Certification Authority certificate ac
СредняяCVSS 4,3Эксплойта нетEPSS 1 %barracuda · web filter25 мая 2015 г.
- CVE-2015-096117Наблюдать
Barracuda Web Filter before 8.1.0.005, when SSL Inspection is enabled, does not verify X.509 certificates from upstream SSL servers, which a
СредняяCVSS 4,3Эксплойта нетEPSS 1 %barracuda · web filter25 мая 2015 г.