CVE-2023-7102
Barracuda Email Security Gateway 300 Firmware 5.1.3.001 – 9.2.1.001
Raw vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HSummary
CVE-2023-7102 is a critical-severity Use of Unmaintained Third Party Components (CWE-1104) vulnerability in Barracuda Email Security Gateway 300 Firmware. Its CVSS base score is 9.8 (Critical).
Operationally, exploitation aligns with the MITRE ATT&CK technique Compromise Software Dependencies and Development Tools (T1195.001); ranked in the top 1% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.
Deeper analysis AI-assisted summary
Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.
CVE-2023-7102 is a parameter-injection vulnerability in Barracuda Email Security Gateway (ESG) appliances that stems from the use of the third-party Spreadsheet::ParseExcel Perl library. The flaw affects firmware versions 5.1.3.001 through 9.2.1.001; Barracuda subsequently removed the vulnerable code path. The issue carries a CVSS 3.1 base score of 9.8, reflecting network attackability without authentication or user interaction and full compromise of confidentiality, integrity, and availability.
An unauthenticated remote attacker can supply a crafted Excel document that triggers the injection when parsed by the affected library, allowing arbitrary command execution on the appliance. Successful exploitation therefore grants an adversary the ability to run code with the privileges of the Barracuda ESG process, typically resulting in full device takeover.
Barracuda’s advisory states that the vulnerable logic has been removed from supported releases and recommends that customers still running the listed firmware versions apply the remediation or migrate to a fixed build. Public proof-of-concept code targeting the underlying Spreadsheet::ParseExcel utility and a detailed Mandiant disclosure are available, while the CVE’s EPSS score remains elevated near 0.82, indicating sustained exploitation interest after publication.
OWASP Top 10 for Web (2025)
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2023-59286
Vulnerability Data
Use of a Third Party library produced a vulnerability in Barracuda Networks Inc. Barracuda ESG Appliance which allowed Parameter Injection.This issue affected Barracuda ESG Appliance, from 5.1.3.001 through 9.2.1.001, until Barracuda removed the vulnerable logic.
- CWE(s)
Related Threats
Threat-Actor AttributionAI
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
—
—
- 1 hardening rule · 1 OS baseline
V15.1.2
Likely Mitigating Controls AI
Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.
Security groups frequently discuss maintenance status of third-party components, aiding identification and avoidance of unmaintained ones.
Maintaining an accurate, reviewed inventory of all system components enables tracking of third-party software versions and maintenance status, reducing the risk of using unmaintained components.
The maintenance policy requires regular updates and upkeep of systems and third-party components, directly reducing the presence of unmaintained software that attackers can exploit.
Requiring quick access to maintenance support and spare parts after failure necessitates using actively supported components rather than unmaintained third-party ones.
Contact with security communities directly informs personnel of unmaintained components and their vulnerabilities, reducing the likelihood of their continued use.
Threat intelligence sharing directly informs organizations of newly discovered vulnerabilities and exploitation in third-party components, enabling timely updates or replacement before attackers can leverage them.
Resource allocation in investment requests funds regular maintenance, patching, and updates of third-party components.
Organization-wide SCRM policy includes ongoing evaluation of third-party component support lifecycles to avoid unmaintained dependencies.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
GV.RM-04's high-level risk-response criteria can indirectly discourage unmaintained third-party use via policy, but alone removes none of the concrete supply-chain or maintenance decisions that produce CWE-1104.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
A maintained asset inventory plus scheduled scanning and patching directly reduces the window during which known vulnerable third-party components remain exploitable.
Periodic validation, certification demands, and life-cycle monitoring of supplier components help surface and replace unmaintained third-party elements before they become exploitable liabilities.
Regular exposure to external advisories and vulnerability disclosures helps teams identify and replace unmaintained third-party components before attackers can exploit known weaknesses in them.
Hardening callouts derived
Configuration rules from DISA STIG baselines that bear on weaknesses of the type cited by this CVE. Each rule is shown with the relationship its mapping actually records, against the CWE it was authored against. Derived via CVE→CWE over `controls_xwalks` (authoritative rows only; rows rated `none` are excluded).
Oracle Linux 8 (1 rule)
- V-248521 OL 8 must be a vendor-supported release. prevents CWE-1104