CVE-2023-7102: Barracuda Email Security Gateway 300 Firmware
Critical severity, CVSS 9.8. EPSS: 44.6% chance of exploitation in the next 30 days.
Use of a Third Party library produced a vulnerability in Barracuda Networks Inc. Barracuda ESG Appliance which allowed Parameter Injection.This issue affected Barracuda ESG Appliance, from 5.1.3.001 through 9.2.1.001, until Barracuda removed the vulnerable logic.
Affected products
- Barracuda Email Security Gateway 300 Firmware: from 5.1.3.001, up to and including 9.2.1.001
- Barracuda Email Security Gateway 400 Firmware: from 5.1.3.001, up to and including 9.2.1.001
- Barracuda Email Security Gateway 600 Firmware: from 5.1.3.001, up to and including 9.2.1.001
- Barracuda Email Security Gateway 800 Firmware: from 5.1.3.001, up to and including 9.2.1.001
- Barracuda Email Security Gateway 900 Firmware: from 5.1.3.001, up to and including 9.2.1.001
Published 2023-12-24. Last modified 2026-06-17.