Barracuda discloses breach of some email security customers due to zero-day vulnerability

The cybersecurity vendor says that an unspecified number of customers of its Email Security Gateway appliance have been impacted

clock • 1 min read
Barracuda discloses breach of some email security customers due to zero-day vulnerability

Barracuda said that some Email Security Gateway customers were impacted by a breach last week that exploited a zero-day vulnerability in the appliance.

The cybersecurity vendor didn't specify how many customers were affected in its disclosure, and said in an email to CRN that it's not sharing further details.

In a post Tuesday, Barracuda said that the vulnerability was discovered on May 19, and the company deployed a patch "to all ESG appliances worldwide" the following day. A second patch was deployed on May 21 to all Email Security Gateway appliances.

The investigation so far has found that the vulnerability "resulted in unauthorised access to a subset of email gateway appliances." Affected customers have been notified, Barracuda said.

"If a customer has not received notice from us via the ESG user interface, we have no reason to believe their environment has been impacted at this time and there are no actions for the customer to take," the company said in an email to CRN Wednesday.

Other Barracuda products were not affected by the vulnerability, including the company's SaaS email security services, the company said in its post.

Barracuda noted that its investigation has been "limited to the ESG product, and not the customer's specific environment."

"Impacted customers should review their environments and determine any additional actions they want to take," Barracuda said in its post.

The zero day vulnerability, which is tracked at CVE-2023-2868, had affected a module used by Barracuda for initial screening of attachments for incoming emails, the company said.

You may also like
Barracuda CRO Chris Ross waves goodbye after nine years

Vendor

Ross shares with CRN his heartfelt farewell to the vendor and teases his next move

clock 12 April 2024 • 2 min read
Barracuda upgrades global partner programme after December launch

Vendor

Cybersecurity vendor jacks up compensation models for partners and distributors

clock 05 March 2024 • 2 min read

Sign up to our newsletter

The best news, stories, features and photos from the day in one perfectly formed email.

More on Vendor

Michael Bernhardt to lead global distribution sales at HPE

Michael Bernhardt to lead global distribution sales at HPE

He will work with HPE's sales, marketing, services and enablement teams to help distributors achieve sustainable business success

Andrea Gaini
clock 02 May 2024 • 2 min read
HP prepping partners for AI era with channel programme update

HP prepping partners for AI era with channel programme update

Vendor rolls out new AI training and sustainability programme to help partners unlock growth opportunities

Andrea Gaini
clock 02 May 2024 • 2 min read
AWS hits $100bn annual run rate as AI push accelerates

AWS hits $100bn annual run rate as AI push accelerates

‘We're at $100bn-plus annualised revenue run rate, yet 85 per cent or more of the global IT spend remains on premises. And this is before we even calculate GenAI,’ says Amazon CEO Andy Jassy

Joseph F. Kovar
clock 02 May 2024 • 6 min read

Highlights

Staff & Salaries 2022

Staff & Salaries 2022

A snapshot of pay and headcount trends in the UK channel

Doug Woodburn
clock 09 March 2022 • 1 min read
Midwich CEO on Nimans acquisition, 2021 results and return to pre-pandemic levels

Midwich CEO on Nimans acquisition, 2021 results and return to pre-pandemic levels

Stephen Fenby talks to CRN after Midwich’s 2021 results in which profitability exceeded pre-pandemic levels

Josh Budd
clock 08 March 2022 • 3 min read
4 more vendors suspend sales in Russia following Ukraine invasion

4 more vendors suspend sales in Russia following Ukraine invasion

IBM and Microsoft are among a number of vendors which have also announced that they will halt sales in Russia following the invasion of Ukraine.

clock 08 March 2022 • 3 min read