Description
On Barracuda CloudGen WAN Private Edge Gateway devices before 8 webui-sdwan-1089-8.3.1-174141891, an OS command injection vulnerability exists in /ajax/update_certificate - a crafted HTTP request allows an authenticated attacker to execute arbitrary commands. For example, a name field can contain :password and a password field can contain shell metacharacters.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-30038 | On Barracuda CloudGen WAN Private Edge Gateway devices before 8 webui-sdwan-1089-8.3.1-174141891, an OS command injection vulnerability exists in /ajax/update_certificate - a crafted HTTP request allows an authenticated attacker to execute arbitrary commands. For example, a name field can contain :password and a password field can contain shell metacharacters. |
References
History
Fri, 07 Mar 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Subscriptions
Barracuda
Subscribe
T100b
Subscribe
T100b Firmware
Subscribe
T193a
Subscribe
T193a Firmware
Subscribe
T200c
Subscribe
T200c Firmware
Subscribe
T400c
Subscribe
T400c Firmware
Subscribe
T600d
Subscribe
T600d Firmware
Subscribe
T900b
Subscribe
T900b Firmware
Subscribe
T93a
Subscribe
T93a Firmware
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-07T15:55:49.918Z
Reserved: 2023-02-20T00:00:00.000Z
Link: CVE-2023-26213
Updated: 2024-08-02T11:46:23.292Z
Status : Modified
Published: 2023-03-03T22:15:09.840
Modified: 2025-03-07T16:15:37.243
Link: CVE-2023-26213
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD