boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, October 7, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2023-2868

Barracuda Barracuda Email Security Gateway — Remote Code injection in Barracuda Email Security Gateway
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  L    9.4   .8769   99.8   YES
AFFECTED
  Product                           Versions     Fixed
  Barracuda Email Security Gateway  5.1.3.001 –  —
TIMELINE
  May 24  Reserved by Google
  May 24  Published (CNA: Google)
  May 26  Added to CISA KEV, remediation due 2023-06-16
CWE-20 · CNA: Google · CVSS v3.1 · 3 references · KEV due June 16, 2023

Description

A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.001-9.2.0.006. The vulnerability arises out of a failure to comprehensively sanitize the processing of .tar file (tape archives). The vulnerability stems from incomplete input validation of a user-supplied .tar file as it pertains to the names of the files contained within the archive. As a consequence, a remote attacker can specifically format these file names in a particular manner that will result in remotely executing a system command through Perl's qx operator with the privileges of the Email Security Gateway product. This issue was fixed as part of BNSF-36456 patch. This patch was automatically applied to all customer appliances.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
May 24, 2023ReservedReserved by Google
May 24, 2023PublishedPublished (CNA: Google)
May 26, 2023KEV ADDEDAdded to CISA KEV, remediation due 2023-06-16

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
BarracudaBarracuda Email Security Gateway—5.1.3.001—

Weaknesses

CWE-20

References (3)

Related

Authoritative record: CVE-2023-2868 at cve.org

Vendors: barracuda

Weaknesses: CWE-20

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2023-2868 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, October 7, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.