CVE-2023-26213

On Barracuda CloudGen WAN Private Edge Gateway devices before 8 webui-sdwan-1089-8.3.1-174141891, an OS command injection vulnerability exists in /ajax/update_certificate - a crafted HTTP request allows an authenticated attacker to execute arbitrary commands. For example, a name field can contain :password and a password field can contain shell metacharacters.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:barracuda:t100b_firmware:8.3.1:-:*:*:*:*:*:*
cpe:2.3:h:barracuda:t100b:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:barracuda:t200c_firmware:8.3.1:-:*:*:*:*:*:*
cpe:2.3:h:barracuda:t200c:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:barracuda:t400c_firmware:8.3.1:-:*:*:*:*:*:*
cpe:2.3:h:barracuda:t400c:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:barracuda:t600d_firmware:8.3.1:-:*:*:*:*:*:*
cpe:2.3:h:barracuda:t600d:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:barracuda:t900b_firmware:8.3.1:-:*:*:*:*:*:*
cpe:2.3:h:barracuda:t900b:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:barracuda:t93a_firmware:8.3.1:-:*:*:*:*:*:*
cpe:2.3:h:barracuda:t93a:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:barracuda:t193a_firmware:8.3.1:-:*:*:*:*:*:*
cpe:2.3:h:barracuda:t193a:-:*:*:*:*:*:*:*

History

10 Mar 2023, 14:53

Type Values Removed Values Added
References (MISC) https://sec-consult.com/vulnerability-lab/advisory/os-command-injection-in-barracuda-cloudgen-wan/ - (MISC) https://sec-consult.com/vulnerability-lab/advisory/os-command-injection-in-barracuda-cloudgen-wan/ - Exploit, Third Party Advisory
References (CONFIRM) https://campus.barracuda.com/product/cloudgenwan/doc/96024723/release-notes-8-3-1/ - (CONFIRM) https://campus.barracuda.com/product/cloudgenwan/doc/96024723/release-notes-8-3-1/ - Release Notes
References (FULLDISC) http://seclists.org/fulldisclosure/2023/Mar/2 - (FULLDISC) http://seclists.org/fulldisclosure/2023/Mar/2 - Exploit, Mailing List, Third Party Advisory
References (MISC) https://www.barracuda.com/products/network-security/cloudgen-wan - (MISC) https://www.barracuda.com/products/network-security/cloudgen-wan - Product
CPE cpe:2.3:h:barracuda:t600d:-:*:*:*:*:*:*:*
cpe:2.3:o:barracuda:t400c_firmware:8.3.1:-:*:*:*:*:*:*
cpe:2.3:o:barracuda:t100b_firmware:8.3.1:-:*:*:*:*:*:*
cpe:2.3:h:barracuda:t200c:-:*:*:*:*:*:*:*
cpe:2.3:h:barracuda:t100b:-:*:*:*:*:*:*:*
cpe:2.3:h:barracuda:t900b:-:*:*:*:*:*:*:*
cpe:2.3:o:barracuda:t600d_firmware:8.3.1:-:*:*:*:*:*:*
cpe:2.3:h:barracuda:t400c:-:*:*:*:*:*:*:*
cpe:2.3:o:barracuda:t200c_firmware:8.3.1:-:*:*:*:*:*:*
cpe:2.3:o:barracuda:t900b_firmware:8.3.1:-:*:*:*:*:*:*
cpe:2.3:h:barracuda:t93a:-:*:*:*:*:*:*:*
cpe:2.3:h:barracuda:t193a:-:*:*:*:*:*:*:*
cpe:2.3:o:barracuda:t93a_firmware:8.3.1:-:*:*:*:*:*:*
cpe:2.3:o:barracuda:t193a_firmware:8.3.1:-:*:*:*:*:*:*
CWE CWE-78
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2

03 Mar 2023, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-03-03 22:15

Updated : 2024-02-04 23:14


NVD link : CVE-2023-26213

Mitre link : CVE-2023-26213

CVE.ORG link : CVE-2023-26213


JSON object : View

Products Affected

barracuda

  • t193a_firmware
  • t600d_firmware
  • t193a
  • t200c_firmware
  • t600d
  • t400c_firmware
  • t100b_firmware
  • t93a
  • t100b
  • t200c
  • t93a_firmware
  • t400c
  • t900b_firmware
  • t900b
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')