Aug. 30, 2023, 7:13 p.m. | Satnam Narang

Cyber Exposure Alerts www.tenable.com

CVE-2023-2868: Barracuda and FBI Recommend Replacing Email Security Gateway (ESG) Devices Immediately

Since October 2022, attackers have been exploiting a zero-day vulnerability in Barracuda Email Security Gateway devices, and both the vendor and the FBI urge customers to replace these devices immediately


Background


On May 19, Barracuda published an incident report that detailed an investigation into a zero-day vulnerability in its Email Security Gateway (ESG) appliances:









CVEDescriptionCVSSv3Severity
CVE-2023-2868Barracuda ESG Appliance Remote Command Injection Vulnerability9.8Critical …

attackers barracuda customers cve cve-2023-2868 devices email email security email security gateway esg exploiting fbi gateway may october security security gateway vendor vulnerability zero-day zero-day vulnerability

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Cloud Security Engineer

@ Gainwell Technologies | Any city, OR, US, 99999

Federal Workday Security Lead

@ Accenture Federal Services | Arlington, VA

Workplace Consultant

@ Solvinity | Den Bosch, Noord-Brabant, Nederland

SrMgr-Global Information Security - Security Risk Management

@ Marriott International | Bethesda, MD, United States

Sr. Security Engineer - Data Loss Prevention

@ Verisk | Jersey City, NJ, United States