CVE-2023-26213

On Barracuda CloudGen WAN Private Edge Gateway devices before 8 webui-sdwan-1089-8.3.1-174141891, an OS command injection vulnerability exists in /ajax/update_certificate - a crafted HTTP request allows an authenticated attacker to execute arbitrary commands. For example, a name field can contain :password and a password field can contain shell metacharacters.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:barracuda:t100b_firmware:8.3.1:-:*:*:*:*:*:*
cpe:2.3:h:barracuda:t100b:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:barracuda:t200c_firmware:8.3.1:-:*:*:*:*:*:*
cpe:2.3:h:barracuda:t200c:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:barracuda:t400c_firmware:8.3.1:-:*:*:*:*:*:*
cpe:2.3:h:barracuda:t400c:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:barracuda:t600d_firmware:8.3.1:-:*:*:*:*:*:*
cpe:2.3:h:barracuda:t600d:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:barracuda:t900b_firmware:8.3.1:-:*:*:*:*:*:*
cpe:2.3:h:barracuda:t900b:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:barracuda:t93a_firmware:8.3.1:-:*:*:*:*:*:*
cpe:2.3:h:barracuda:t93a:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:barracuda:t193a_firmware:8.3.1:-:*:*:*:*:*:*
cpe:2.3:h:barracuda:t193a:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-03-03 22:15

Updated : 2024-02-28 19:51


NVD link : CVE-2023-26213

Mitre link : CVE-2023-26213

CVE.ORG link : CVE-2023-26213


JSON object : View

Products Affected

barracuda

  • t200c
  • t93a_firmware
  • t193a
  • t900b
  • t400c_firmware
  • t100b_firmware
  • t600d_firmware
  • t600d
  • t93a
  • t193a_firmware
  • t200c_firmware
  • t900b_firmware
  • t400c
  • t100b
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')