CVE-2023-2868

Vulnerability updated 5 months ago (2024-05-04T16:24:29.632Z)
Download STIX
Preview STIX
CVE-2023-2868 is a significant software vulnerability that was identified in the Barracuda Email Security Gateway (ESG) appliances. This flaw, specifically a remote command injection vulnerability, was disclosed by Barracuda on May 30th, 2023. The vulnerability had been exploited as early as October 2022 and was due to the way initial screening of incoming email attachments was handled. Notably, UNC4841, a Chinese threat actor group, exploited this zero-day vulnerability in the email attachment screening module, leading to global security concerns. Intrusion sets with links to China have been observed heavily targeting Remote Code Execution (RCE) vulnerabilities and exploiting zero-day vulnerabilities, as highlighted by Mandiant's publications. Among these, CVE-2023-2868 stands out for its exploitation by UNC4841 to gain unauthorized access to ESG appliances and deploy additional malware. This aggressive and skilled activity has raised suspicions of links to China. In addition to CVE-2023-2868, other notable vulnerabilities such as CVE-2021-44207, CVE-2021-44228, and CVE-2022-41328 were also exploited by different Chinese groups. In response to the ongoing campaign utilizing CVE-2023-2868 against Barracuda appliances, the vendor recommended customers return their appliances for new ones. Further investigations into the exploitation of this vulnerability were carried out by security firms like Vectra AI, TeamT5, and Mandiant. These investigations provided further details on the tactics, techniques, and procedures (TTPs) used by the threat actor UNC4841. This continued exploitation of vulnerabilities underscores the need for robust cybersecurity measures and prompt responses to identified threats.
Description last updated: 2024-04-23T14:16:06.474Z
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Vulnerability
Barracuda
CISA
Backdoor
Malware
Zero Day
flaw
Exploit
Mandiant
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Associated Threat Actors
To see the evidence that has resulted in these threatActor associations, create a free account
Alias DescriptionAssociation TypeVotes
The Unc4841 Threat Actor is associated with CVE-2023-2868. UNC4841, a threat actor suspected to be a Chinese hacker group, has been identified as the entity behind a series of malicious cyber activities. The group targeted US government email servers by exploiting a zero-day vulnerability in Barracuda Email Security Gateway (ESG) appliances. Their activitieUnspecified
3
Source Document References
Information about the CVE-2023-2868 Vulnerability was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
CISA
2 months ago
InfoSecurity-magazine
5 months ago
CERT-EU
9 months ago
CERT-EU
9 months ago
CERT-EU
9 months ago
CERT-EU
9 months ago
CERT-EU
9 months ago
CERT-EU
9 months ago
Securityaffairs
9 months ago
CERT-EU
9 months ago
CERT-EU
9 months ago
Pulsedive
10 months ago
CERT-EU
a year ago
Securelist
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
InfoSecurity-magazine
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago