Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

CVE-2023-2868 was a command-injection flaw in Barracuda Email Security Gateway (ESG) appliances. Attackers exploited it as a zero-day from at least October 10, 2022. Mandiant tracked the activity as UNC4841 and assessed with high confidence that the group conducted espionage in support of the People’s Republic of China (PRC). For organizations whose appliances were compromised, applying a patch was not enough: Barracuda, Mandiant, and the FBI advised isolating and replacing affected appliances and investigating the wider network.

What is CVE-2023-2868?

CVE-2023-2868 was a remote command-injection vulnerability in the appliance version of Barracuda Email Security Gateway. It affected ESG versions 5.1.3.001 through 9.2.0.006, specifically the process that scans email attachments. Barracuda’s incident updates and Mandiant’s June 15, 2023 campaign analysis describe the flaw and its exploitation.

The appliance processed TAR archives using filenames supplied within the archive. Inadequate validation allowed a crafted filename to enter a Perl command-execution path, enabling an attacker to run system commands. Mandiant reported that the attackers sent specially crafted TAR attachments by email. Some used misleading extensions such as .jpg or .dat while remaining valid TAR archives. The relevant code ran when the gateway scanned the attachment; the reported exploit path did not require a recipient to open it.

Was Barracuda ESG hacked by a Chinese group?

Mandiant tracked the operator as UNC4841. In its June 15, 2023 report, Mandiant stated: “Mandiant assesses with high confidence that UNC4841 conducted espionage activity in support of the People’s Republic of China.” That is Mandiant’s attribution assessment, not a claim that every aspect of the campaign or each intrusion has been independently attributed to a previously known group. Mandiant said it had not attributed the activity to a previously known threat group at that time.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Mandiant described targeted data collection and exfiltration involving, among others, government, foreign-trade, and academic organizations. It reported that at least 16 countries were targeted in high-frequency operations between May 22 and May 24, 2023; this figure describes that period, not necessarily the campaign’s full geographic reach. Almost a third of the organizations Mandiant identified as affected were government agencies. That proportion is not a count or share of all vulnerable appliances. Mandiant also observed some attackers using ESG access for lateral movement or to send email to other victim appliances; those behaviors were not established for every victim.

How long was the vulnerability exploited before it became public?

Mandiant found evidence of exploitation beginning October 10, 2022, months before public disclosure in May 2023. Barracuda said it was alerted to anomalous traffic on May 18, identified the vulnerability on May 19, and applied a security patch worldwide on May 20, 2023. The timeline matters because an attacker could have established access before the patch was applied.

Does patching the vulnerability remove an existing compromise?

No. A patch can close the vulnerable code path, but it does not remove malware or persistence already installed during an intrusion. Mandiant identified SALTWATER, SEASPY, and SEASIDE among the principal malware families it observed in most intrusions; the actor disguised them as legitimate Barracuda modules or services. CISA’s July 28, 2023 malware analysis reports described SEASPY as a persistent passive backdoor masquerading as a Barracuda service, and SUBMARINE as a novel root-privilege backdoor residing in an ESG SQL database, with components for persistence, command and control, and cleanup. These findings show why response cannot be limited to patching the original flaw.

What should an organization do if its Barracuda ESG was affected?

For a confirmed compromised appliance, the official guidance was to isolate and replace it regardless of patch level, then investigate beyond the appliance itself. Barracuda advised impacted customers to stop using compromised units and contact support for a replacement virtual or hardware appliance; its August 29, 2023 update said replacements were provided at no cost to impacted customers.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Contain and replace the appliance

  • Discontinue use of the compromised ESG and isolate it from the network.
  • Contact Barracuda support to obtain a replacement appliance. Do not treat patching the existing unit as a substitute for replacement after a confirmed compromise.

Investigate the wider environment

  • Review email logs to identify the initial exposure and determine what traffic or messages may have reached the gateway.
  • Hunt across the affected network using Barracuda’s and Mandiant’s indicators of compromise (IOCs), and examine evidence of lateral movement or related activity.
  • Rotate domain-based and local credentials that were present on the ESG during the compromise, and revoke and reissue certificates that were present at that time.

The FBI’s August 23, 2023 flash alert independently warned that exploited appliances remained at risk even when patched, and advised isolation, replacement, and network-log scanning for IOCs. Historical IOC lists are time-bound; they should not be treated as a complete present-day detection method. Follow current vendor and incident-response guidance when investigating a suspected compromise.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Were Barracuda SaaS email services affected?

Barracuda said its SaaS email solutions and other products were not affected by CVE-2023-2868; the vulnerability described here affected the ESG appliance form factor. Barracuda’s product-scope statement is in its incident updates.

There were later, separate ESG vulnerabilities: in December 2023, Australia’s ASD’s ACSC reported active exploitation of CVE-2023-7101 and CVE-2023-7102, involving the third-party Spreadsheet::ParseExcel library. Its advisory said Barracuda deployed an update to active appliances on December 21, 2023. Those issues are distinct from CVE-2023-2868.

How many appliances were compromised?

The cited reports do not establish a verified exact total of compromised appliances. Barracuda described the affected number as “limited,” while Mandiant’s published proportions refer to organizations it identified as affected, not a count of appliances. A precise global appliance total cannot be inferred from those figures.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.