On Barracuda CloudGen WAN Private... CVE-2023-26213

- AV AC AU C I A
发布: 2023-03-03
修订: 2023-03-10

On Barracuda CloudGen WAN Private Edge Gateway devices before 8 webui-sdwan-1089-8.3.1-174141891, an OS command injection vulnerability exists in /ajax/update_certificate - a crafted HTTP request allows an authenticated attacker to execute arbitrary commands. For example, a name field can contain :password and a password field can contain shell metacharacters.

0%
当前有1条漏洞利用/PoC
当前有14条受影响产品信息