Known Vulnerabilities for products from Barracuda

Listed below are 10 of the newest known vulnerabilities associated with the vendor "Barracuda".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Additional devices specifications by Barracuda can be found at device.report : Barracuda

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2021-42711 ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 7.8 - HIGH 2021-12-01 2021-12-03
CVE-2019-6724 The barracudavpn component of the Barracuda VPN Client prior to version 5.0.2.7 for Linux, macOS, and OpenBSD runs as a privi... 7.8 - HIGH 2019-03-21 2020-08-24
CVE-2019-5648 Authenticated, administrative access to a Barracuda Load Balancer ADC running unpatched firmware <= v6.4 allows one to edit t... 6.5 - MEDIUM 2020-03-12 2020-03-12
CVE-2018-20369 Barracuda Message Archiver 2018 has XSS in the error_msg exception-handling value for the ldap_user parameter to the cgi-mod/... 6.1 - MEDIUM 2018-12-23 2019-01-15
CVE-2017-6320 A remote command injection vulnerability exists in the Barracuda Load Balancer product line (confirmed on v5.4.0.004 (2015-11... 8.8 - HIGH 2017-07-18 2020-07-01
CVE-2015-0962 Barracuda Web Filter 7.x and 8.x before 8.1.0.005, when SSL Inspection is enabled, uses the same root Certification Authority... 4.3 - MEDIUM 2015-05-25 2015-05-27
CVE-2015-0961 Barracuda Web Filter before 8.1.0.005, when SSL Inspection is enabled, does not verify X.509 certificates from upstream SSL s... 4.3 - MEDIUM 2015-05-25 2015-05-27
CVE-2014-8428 Privilege escalation vulnerability in Barracuda Load Balancer 5.0.0.015 via the use of an improperly protected SSH key. 9.8 - CRITICAL 2017-08-28 2017-09-01
CVE-2014-8426 Hard coded weak credentials in Barracuda Load Balancer 5.0.0.015. 9.8 - CRITICAL 2017-08-28 2017-09-01
CVE-2014-2595 Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a permanent... 9.8 - CRITICAL 2020-02-12 2020-02-20

Known software with vulnerabilities from Barracuda

Type Vendor Product Version
ApplicationBarracudaLoad Balancer5.0.0.015
HardwareBarracudaLoad Balancer Adc-
Operating
System
BarracudaLoad Balancer Adc Firmware6.2.0.005
ApplicationBarracudaMessage Archiver2018
ApplicationBarracudaVpn Client5.0
ApplicationBarracudaWeb Application Firewall7.8.1.013
ApplicationBarracudaWeb Filter7.0
ApplicationBarracudaYosemite Server Backup8.8.3