What is Barracuda Email Security Gateway Appliance (ESG)?
The Barracuda Email Security Gateway Appliance is an email security solution that monitors and filters inbound and outbound emails for unwanted content such as spam and malware.
What is the Attack?
The vulnerability arises out of a failure to comprehensively sanitize the processing of .tar file (tape archives) and their names. An attacker can leverage these file names in a specific manner to allow for remote command execution (RCE).
Why is this Significant?
This is significant because CVE-2023-2868 was exploited as early as October 2022 for backdoor deployment according to reports. CISA has already added the vulnerability on its Known Exploited Vulnerabilities (KEV) catalog due to observed active exploitation in the wild.
What is the Vendor Solution?
Although a patch to address the vulnerability was released, the vendor recommends replacing all impacted devices regardless of patch level.
What FortiGuard Coverage is available?
FortiGuard Labs released an IPS signature “Barracuda.Email.Security.Gateway.Tar.File.Command.Injection” for CVE-2023-2868.
Some of the reported file IOCs are detected as Linux/SaltWater.A!tr, ELF/Vigorf.A!tr, and Data/ESG.ADA0!tr.
All network IOCs in the security advisory are blocked by the Webfiltering client.
Is Mitigation Available?
The Barracuda security advisory provides mitigation methods. Please refer to the Appendix for a link to “Barracuda Email Security Gateway Appliance (ESG) Vulnerability”.
More Stories
mysql8.0-8.0.41-1.fc41
FEDORA-2025-8352a35e30 Packages in this update: mysql8.0-8.0.41-1.fc41 Update description: MySQL 8.0.41 Reease notes: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-41.html Read More
mysql8.0-8.0.41-1.fc40
FEDORA-2025-ebdcfc0f27 Packages in this update: mysql8.0-8.0.41-1.fc40 Update description: MySQL 8.0.41 Reease notes: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-41.html Read More
workrave-1.11.0~rc.1-1.el9
FEDORA-EPEL-2025-85c41364aa Packages in this update: workrave-1.11.0~rc.1-1.el9 Update description: Unretireing the package. Read More
workrave-1.11.0~rc.1-1.fc41
FEDORA-2025-d611c8d114 Packages in this update: workrave-1.11.0~rc.1-1.fc41 Update description: Unretireing the package. Read More
workrave-1.11.0~rc.1-1.fc42
FEDORA-2025-85867bd98f Packages in this update: workrave-1.11.0~rc.1-1.fc42 Update description: Unretireing the package. Read More
workrave-1.11.0~rc.1-1.fc40
FEDORA-2025-2d5726abb8 Packages in this update: workrave-1.11.0~rc.1-1.fc40 Update description: Unretireing the package. Read More