Reference page — cumulative record through Wednesday, October 7, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2023-2868
Barracuda Barracuda Email Security Gateway — Remote Code injection in Barracuda Email Security Gateway
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U H H L 9.4 .8769 99.8 YES
AFFECTED
Product Versions Fixed
Barracuda Email Security Gateway 5.1.3.001 – —
TIMELINE
May 24 Reserved by Google
May 24 Published (CNA: Google)
May 26 Added to CISA KEV, remediation due 2023-06-16
Description
A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.001-9.2.0.006. The vulnerability arises out of a failure to comprehensively sanitize the processing of .tar file (tape archives). The vulnerability stems from incomplete input validation of a user-supplied .tar file as it pertains to the names of the files contained within the archive. As a consequence, a remote attacker can specifically format these file names in a particular manner that will result in remotely executing a system command through Perl's qx operator with the privileges of the Email Security Gateway product. This issue was fixed as part of BNSF-36456 patch. This patch was automatically applied to all customer appliances.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| May 24, 2023 | Reserved | Reserved by Google |
| May 24, 2023 | Published | Published (CNA: Google) |
| May 26, 2023 | KEV ADDED | Added to CISA KEV, remediation due 2023-06-16 |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Barracuda | Barracuda Email Security Gateway | — | 5.1.3.001 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2023-2868 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, October 7, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.