CVE Vulnerabilities

CVE-2023-7102

Use of Unmaintained Third Party Components

Published: Dec 24, 2023 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Use of a Third Party library produced a vulnerability in Barracuda Networks Inc. Barracuda ESG Appliance which allowed Parameter Injection.This issue affected Barracuda ESG Appliance, from 5.1.3.001 through 9.2.1.001, until Barracuda removed the vulnerable logic.

Weakness

The product relies on third-party components that are not actively supported or maintained by the original developer or a trusted proxy for the original developer.

Affected Software

Name Vendor Start Version End Version
Email_security_gateway_300_firmware Barracuda 5.1.3.001 (including) 9.2.1.001 (including)

References