# Barracuda Email Security Gateway Appliance has a critical remote code execution…

Published: 2024-01-04 · Severity: critical
Canonical: https://vorant.io/reports/2af8a706-1128-4ba8-9247-3cecafeb4703/barracuda-email-security-gateway-appliance-has-a-critical-remote-code-execution

> Barracuda Email Security Gateway Appliance has a critical remote code execution vulnerability (CVE-2023-7102) stemming from the Spreadsheet::ParseExcel library, with active exploitation confirmed.

Japan's IPA has issued an alert regarding a remote code execution vulnerability in Barracuda Networks' Email Security Gateway Appliance (ESG). The vulnerability, tracked as CVE-2023-7102, allows unauthenticated remote attackers to execute arbitrary code on affected systems. According to the vendor, active exploitation of this vulnerability has been observed in the wild.

The root cause has been identified as CVE-2023-7101, a vulnerability in the open-source Spreadsheet::ParseExcel library used by the ESG product for parsing Excel files. The library maintainers have released version 0.66 to address CVE-2023-7101. Organizations using Spreadsheet::ParseExcel in their own products or services are advised to upgrade to the patched version.

Barracuda has released security updates that are applied automatically to ESG appliances. The IPA advises administrators to ensure these patches are applied. This incident highlights the supply chain risk inherent in third-party library dependencies, particularly when vulnerabilities in widely-used components enable remote code execution in security products designed to protect network perimeters.

## Mentioned in this report

- Vulnerabilities: CVE-2023-7101 (KEV), CVE-2023-7102 (weaponized)

Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2023/alert20231225.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/2af8a706-1128-4ba8-9247-3cecafeb4703/barracuda-email-security-gateway-appliance-has-a-critical-remote-code-execution.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
