Cyber Resilience

CVE-2023-7102

Barracuda Email Security Gateway 300 Firmware 5.1.3.001 – 9.2.1.001

Published
24 December 2023
Modified
21 November 2024
Patch / advisory
CVSS Score v3.1 9.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.44 99th percentile
Risk Priority 97 floored blend · peak EPSS

Summary

CVE-2023-7102 is a critical-severity Use of Unmaintained Third Party Components (CWE-1104) vulnerability in Barracuda Email Security Gateway 300 Firmware. Its CVSS base score is 9.8 (Critical).

Operationally, exploitation aligns with the MITRE ATT&CK technique Compromise Software Dependencies and Development Tools (T1195.001); ranked in the top 1% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

CVE-2023-7102 is a parameter-injection vulnerability in Barracuda Email Security Gateway (ESG) appliances that stems from the use of the third-party Spreadsheet::ParseExcel Perl library. The flaw affects firmware versions 5.1.3.001 through 9.2.1.001; Barracuda subsequently removed the vulnerable code path. The issue carries a CVSS 3.1 base score of 9.8, reflecting network attackability without authentication or user interaction and full compromise of confidentiality, integrity, and availability.

An unauthenticated remote attacker can supply a crafted Excel document that triggers the injection when parsed by the affected library, allowing arbitrary command execution on the appliance. Successful exploitation therefore grants an adversary the ability to run code with the privileges of the Barracuda ESG process, typically resulting in full device takeover.

Barracuda’s advisory states that the vulnerable logic has been removed from supported releases and recommends that customers still running the listed firmware versions apply the remediation or migrate to a fixed build. Public proof-of-concept code targeting the underlying Spreadsheet::ParseExcel utility and a detailed Mandiant disclosure are available, while the CVE’s EPSS score remains elevated near 0.82, indicating sustained exploitation interest after publication.

OWASP Top 10 for Web (2025)

EU & UK References

Vulnerability Data

Use of a Third Party library produced a vulnerability in Barracuda Networks Inc. Barracuda ESG Appliance which allowed Parameter Injection.This issue affected Barracuda ESG Appliance, from 5.1.3.001 through 9.2.1.001, until Barracuda removed the vulnerable logic.

CWE(s)

Related Threats

Threat-Actor AttributionAI

UNC4841
Mandiant (MNDT-2023-0019) attributes exploitation of the Barracuda ESG Spreadsheet::ParseExcel RCE flaws (CVE-2023-7101/7102) to UNC4841.

MITRE ATT&CK Enterprise Techniques

T1195.001 Compromise Software Dependencies and Development Tools Initial Access
Adversaries may manipulate software dependencies and development tools prior to receipt by a final consumer for the purpose of data or system compromise.
T1195 Supply Chain Compromise Initial Access
Adversaries may manipulate products or product delivery mechanisms prior to receipt by a final consumer for the purpose of data or system compromise.
Derived from this CVE’s CWE(s) via the direct CWE→ATT&CK cross-walk.

CVEs Like This One

CVE-2023-2868Same product: Barracuda Email Security Gateway 300
CVE-2025-34192Shared CWE-1104
CVE-2026-3031Shared CWE-1104
CVE-2025-20010Shared CWE-1104
CVE-2024-11999Shared CWE-1104
CVE-2026-16634Shared CWE-1104
CVE-2026-60368Shared CWE-1104
CVE-2025-3497Shared CWE-1104
CVE-2026-41468Shared CWE-1104
CVE-2023-37524Shared CWE-1104

Affected Assets

barracuda
email security gateway 300 firmware
5.1.3.001 — 9.2.1.001
barracuda
email security gateway 400 firmware
5.1.3.001 — 9.2.1.001
barracuda
email security gateway 600 firmware
5.1.3.001 — 9.2.1.001
barracuda
email security gateway 800 firmware
5.1.3.001 — 9.2.1.001
barracuda
email security gateway 900 firmware
5.1.3.001 — 9.2.1.001

Mitigating Controls

Control response

Prevent
Stop it (NIST 800-53)

Detect
Catch it (NIST detect / respond)

Harden
Shrink the surface (DISA STIG)
  • 1 hardening rule · 1 OS baseline
Validate
Prove the fix (OWASP ASVS)
  • V15.1.2

Likely Mitigating Controls AI

Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.

addresses: CWE-1104

Security groups frequently discuss maintenance status of third-party components, aiding identification and avoidance of unmaintained ones.

addresses: CWE-1104

Maintaining an accurate, reviewed inventory of all system components enables tracking of third-party software versions and maintenance status, reducing the risk of using unmaintained components.

addresses: CWE-1104

The maintenance policy requires regular updates and upkeep of systems and third-party components, directly reducing the presence of unmaintained software that attackers can exploit.

addresses: CWE-1104

Requiring quick access to maintenance support and spare parts after failure necessitates using actively supported components rather than unmaintained third-party ones.

addresses: CWE-1104

Contact with security communities directly informs personnel of unmaintained components and their vulnerabilities, reducing the likelihood of their continued use.

addresses: CWE-1104

Threat intelligence sharing directly informs organizations of newly discovered vulnerabilities and exploitation in third-party components, enabling timely updates or replacement before attackers can leverage them.

addresses: CWE-1104

Resource allocation in investment requests funds regular maintenance, patching, and updates of third-party components.

addresses: CWE-1104

Organization-wide SCRM policy includes ongoing evaluation of third-party component support lifecycles to avoid unmaintained dependencies.

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

GV.RM-04 partial match
prevents

GV.RM-04's high-level risk-response criteria can indirectly discourage unmaintained third-party use via policy, but alone removes none of the concrete supply-chain or maintenance decisions that produce CWE-1104.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

finds

A maintained asset inventory plus scheduled scanning and patching directly reduces the window during which known vulnerable third-party components remain exploitable.

prevents

Periodic validation, certification demands, and life-cycle monitoring of supplier components help surface and replace unmaintained third-party elements before they become exploitable liabilities.

mitigates

Regular exposure to external advisories and vulnerability disclosures helps teams identify and replace unmaintained third-party components before attackers can exploit known weaknesses in them.

Hardening callouts derived

Configuration rules from DISA STIG baselines that bear on weaknesses of the type cited by this CVE. Each rule is shown with the relationship its mapping actually records, against the CWE it was authored against. Derived via CVE→CWE over `controls_xwalks` (authoritative rows only; rows rated `none` are excluded).

Oracle Linux 8 (1 rule)
  • V-248521 OL 8 must be a vendor-supported release. prevents CWE-1104

References