📦

t193a

Vendor: barracuda

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 1 Remote Access
Total CVEs 1 Total Indexed
Avg. EPSS 7.88% Exploit Prob.
Latest CVE CVE-2023-26213 Mar 03

Security Vulnerability Index

Page 1 / 1
7.2 CVSS

On Barracuda CloudGen WAN Private Edge Gateway devices before 8 webui-sdwan-1089-8.3.1-174141891, an OS command injection vulnerability exists in /ajax/update_certificate - a crafted HTTP request allows an authenticated attacker to execute arbitrary commands. For example, a name field can contain :password and a password field can contain shell metacharacters.

EPSS: 7.88%