CVE-2023-26213
Severity CVSS v4.0:
Pending analysis
Type:
CWE-78
OS Command Injections
Publication date:
03/03/2023
Last modified:
07/03/2025
Description
On Barracuda CloudGen WAN Private Edge Gateway devices before 8 webui-sdwan-1089-8.3.1-174141891, an OS command injection vulnerability exists in /ajax/update_certificate - a crafted HTTP request allows an authenticated attacker to execute arbitrary commands. For example, a name field can contain :password and a password field can contain shell metacharacters.
Impact
Base Score 3.x
7.20
Severity 3.x
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:barracuda:t100b_firmware:8.3.1:-:*:*:*:*:*:* | ||
cpe:2.3:h:barracuda:t100b:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:barracuda:t200c_firmware:8.3.1:-:*:*:*:*:*:* | ||
cpe:2.3:h:barracuda:t200c:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:barracuda:t400c_firmware:8.3.1:-:*:*:*:*:*:* | ||
cpe:2.3:h:barracuda:t400c:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:barracuda:t600d_firmware:8.3.1:-:*:*:*:*:*:* | ||
cpe:2.3:h:barracuda:t600d:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:barracuda:t900b_firmware:8.3.1:-:*:*:*:*:*:* | ||
cpe:2.3:h:barracuda:t900b:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:barracuda:t93a_firmware:8.3.1:-:*:*:*:*:*:* | ||
cpe:2.3:h:barracuda:t93a:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:barracuda:t193a_firmware:8.3.1:-:*:*:*:*:*:* | ||
cpe:2.3:h:barracuda:t193a:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://seclists.org/fulldisclosure/2023/Mar/2
- https://campus.barracuda.com/product/cloudgenwan/doc/96024723/release-notes-8-3-1/
- https://sec-consult.com/vulnerability-lab/advisory/os-command-injection-in-barracuda-cloudgen-wan/
- https://www.barracuda.com/products/network-security/cloudgen-wan
- http://seclists.org/fulldisclosure/2023/Mar/2
- https://campus.barracuda.com/product/cloudgenwan/doc/96024723/release-notes-8-3-1/
- https://sec-consult.com/vulnerability-lab/advisory/os-command-injection-in-barracuda-cloudgen-wan/
- https://www.barracuda.com/products/network-security/cloudgen-wan