← Global Threat Landscape

CVE-2023-2868

CWE-20

Critical

101.3

RPS

Description

A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.001-9.2.0.006. The vulnerability arises out of a failure to comprehensively sanitize the processing of .tar file (tape archives). The vulnerability stems from incomplete input validation of a user-supplied .tar file as it pertains to the names of the files contained within the archive. As a consequence, a remote attacker can specifically format these file names in a particular manner that will result in remotely executing a system command through Perl's qx operator with the privileges of the Email Security Gateway product. This issue was fixed as part of BNSF-36456 patch. This patch was automatically applied to all customer appliances.

Source: NVD

Signals

CVSS
9.4
Critical · v3.1
EPSS
87.69%
Probability of exploitation in the next 30 days (FIRST)
CISA KEV
In CISA KEV since May 2023
Fix commit
No known fix commit
Sources: MoreFixes, FreshFixes
Weakness
CWE-20
CWE-20, CWE-77
Published
24 May 2023
Last modified 24 Oct 2025

How to read these signals: RPS · EPSS · CISA KEV · Data sources

Get this score from the API

curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
  https://api.intelligence.devsecure.io/api/v1/rps/CVE-2023-2868

Replace the placeholder with your key. Get a free API key or rank your own CVEs.

Data as of 7 Oct 2026, 05:16 UK time

CVE-2023-2868 · RPS 101.3 · DevSecure Intelligence