Kiratas
  • Home
  • World
  • Lifestyle

    Trending Tags

    • Pandemic
  • Business
  • Entertainment
  • Sports
No Result
View All Result
  • Home
  • World
  • Lifestyle

    Trending Tags

    • Pandemic
  • Business
  • Entertainment
  • Sports
No Result
View All Result
Kiratas
No Result
View All Result
Home World

Zero-Day Vulnerability: Barracuda Distributes Email Security Gateway Update

Keira Austin by Keira Austin
May 25, 2023
in World
0
Zero-Day Vulnerability: Barracuda Distributes Email Security Gateway Update
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter

Attackers exploit a critical zero-day vulnerability in Barracuda’s Email Security Gateway Appliance (ESG). The vulnerability allows malicious actors from the network to inject commands. The manufacturer distributes updates that are intended to close the gap.

Barracuda developers explain that the vulnerability occurs when processing .tar archives because the ESG does not perform sufficient filtering in them. The software uses the names specified in the .tar archives directly in Perl scripts. Through specially manipulated file names in the .tar file, attackers can inject system commands that are executed with the privileges of the ESG software when processed (CVE-2023-2868, CVSS 9.4Risk “critical“).

Barracuda ESG: Update distributed automatically

Barracuda writes in a status report that the company became aware of the vulnerability on Friday last week. On Saturday, the company distributed a security patch to all ESG appliances worldwide. This was followed by a second update on Sunday to contain the problem.

The investigation revealed that several ESG appliances had already been attacked and the attackers had gained access to them. The analysis is still ongoing. On appliances that Barracuda classifies as being affected by specific attacks, the IT analysts have provided instructions in the user interface as to which measures should be taken. The company also reached out to customers. Since Barracuda only examined the appliance, affected customers should thoroughly check their IT environment to see whether the cybercriminals have already spread further.

IT leaders should take a look at their Barracuda ESG Appliance to see if there are any alerts and if the updates have been applied correctly.

(dmk)

To home page

Tags: BarracudaBarracuda Email Security GatewayCybercrimedistributesEmailESGExploitGatewaySecurityupdatevulnerabilitiesVulnerabilityZeroDay
Previous Post

Jordi Alba renounces half of his contract but not his debt: this is the player’s impressive settlement

Next Post

Do not throw away the shoes that no longer fit you: with this trick and food that you have in the kitchen, you will use them again

Keira Austin

Keira Austin

Related Posts

EL PAÍS
World

The Hispanic Society reopens its doors and joins the celebration of the years dedicated to Sorolla and Picasso

by Keira Austin
June 6, 2023
Castilla y León is ready to face the fire
World

Castilla y León is ready to face the fire

by Keira Austin
June 6, 2023
This is how they modify a captured Russian T-62 tank to turn it into an artillery support vehicle
World

This is how they modify a captured Russian T-62 tank to turn it into an artillery support vehicle

by Keira Austin
June 6, 2023
EL PAÍS
World

The US learned of Ukrainian plans to blow up the Nord Stream gas pipelines, according to ‘The Washington Post’

by Keira Austin
June 6, 2023
Blowing up the dam could jeopardize water supplies in the occupied Crimean peninsula
World

Blowing up the dam could jeopardize water supplies in the occupied Crimean peninsula

by Keira Austin
June 6, 2023
Next Post
Do not throw away the shoes that no longer fit you: with this trick and food that you have in the kitchen, you will use them again

Do not throw away the shoes that no longer fit you: with this trick and food that you have in the kitchen, you will use them again

Premium Content

EL PAÍS

The vote of people with disabilities: “We are not yet on an equal footing”

May 27, 2023
Sánchez Cabrera retains the mayoralty of Ávila and will be able to govern alone

Sánchez Cabrera retains the mayoralty of Ávila and will be able to govern alone

May 28, 2023
On June 1st: Start of the heise Security Tour 2023

On June 1st: Start of the heise Security Tour 2023

May 23, 2023

Browse by Category

  • Business
  • Sports
  • World

Browse by Tags

28M Apple arrested artificial Artificial intelligence attack Barcelona campaign ChatGPT China data day elections electoral European euros Feijóo Government health intelligence June League live Madrid Microsoft million people PSOE Real result Russia Security Spain Spanish Sánchez time today Ukraine Vinicius vote Vox vulnerabilities war world years
Kiratas

Latest News from World, Health, Politics, Sports, Business, Education, Technology, Arts and Latin America, the Middle East, South Asia.

Categories

  • Business
  • Sports
  • World

Browse by Tag

28M Apple arrested artificial Artificial intelligence attack Barcelona campaign ChatGPT China data day elections electoral European euros Feijóo Government health intelligence June League live Madrid Microsoft million people PSOE Real result Russia Security Spain Spanish Sánchez time today Ukraine Vinicius vote Vox vulnerabilities war world years

Recent Posts

  • The Hispanic Society reopens its doors and joins the celebration of the years dedicated to Sorolla and Picasso
  • Castilla y León is ready to face the fire
  • This is how they modify a captured Russian T-62 tank to turn it into an artillery support vehicle
  • About us
  • Home
  • Privacy Policy
  • Terms and Conditions

© Kiratas 2023. All Rights Reserved.

No Result
View All Result
  • Home
  • World
  • Lifestyle
  • Business
  • Entertainment
  • Sports

© Kiratas 2023. All Rights Reserved.