Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Critical

Parameter Injection in Barracuda ESG via Spreadsheet::ParseExcel

IdentifiersCVE-2023-7102CWE-74

CVE-2023-7102 is a parameter injection vulnerability in Barracuda Networks Email Security Gateway (ESG) Appliance caused by vulnerable logic introduced through a third-party library, identified in reporting as Spreadsheet::ParseExcel. Barracuda stated the issue affected ESG Appliance versions 5.1.3.001 through 9.2.1.001 until the vulnerable logic was removed. Available reporting indicates the flaw was exploitable through malicious Excel attachments processed by the appliance’s email attachment handling/scanning workflow. Barracuda disclosed that this vulnerability was used as a follow-on exploitation path to reinstall updated SEASPY and SALTWATER malware variants after initial remediation efforts.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allowed attackers to abuse the ESG appliance’s attachment-processing path and execute a parameter injection condition on the device. In observed intrusions, the vulnerability was used to regain or maintain access by reinstalling malware on previously remediated Barracuda ESG appliances. Operationally, this can enable continued compromise of the email security gateway, interception or access to email traffic handled by the appliance, persistence on the edge device, and follow-on espionage activity.

Mitigation

If you can’t patch tonight, do this now.

Reduce exposure to malicious attachment processing where operationally possible, especially Excel attachments traversing Barracuda ESG. Apply Barracuda’s latest fixes and compensating controls immediately. Monitor ESG appliances for signs of reinfection or persistence, including unexpected processes, modified files, outbound connections, and indicators associated with SEASPY and SALTWATER. Given the history of post-remediation reinfection, isolate suspected devices, perform forensic review, and treat previously exposed appliances as potentially compromised until proven otherwise.

Remediation

Patch, then assume compromise.

Barracuda indicated affected ESG Appliance versions were 5.1.3.001 through 9.2.1.001 until Barracuda removed the vulnerable logic. Remediation is therefore to apply Barracuda-provided updates or product changes that remove the vulnerable logic, and to follow Barracuda’s incident-response guidance for compromised ESG appliances. Because this vulnerability was reported as being used to reinstall malware after remediation, organizations should not rely on patching alone; they should validate appliance integrity, investigate for persistence, rotate credentials and secrets that may have been exposed, and replace or rebuild affected appliances if compromise is suspected.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
Barracuda NetworksEmail Security Gateway 300 Firmwareoperating_system
Barracuda NetworksEmail Security Gateway 400 Firmwareoperating_system
Barracuda NetworksEmail Security Gateway 600 Firmwareoperating_system
Barracuda NetworksEmail Security Gateway 800 Firmwareoperating_system
Barracuda NetworksEmail Security Gateway 900 Firmwareoperating_system

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence1

Every observed campaign linking this CVE to a named adversary.

Associated malware3

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity1

Community discussion across Reddit, Mastodon, and other social sources.