logo

Technical analysis: Barracuda Email Security Gateway by Quentin Olagne

ID: d90d8b8e-aa7e-5c31-b8bb-93b5d71f53e0

STIX ID: report--d90d8b8e-aa7e-5c31-b8bb-93b5d71f53e0

Feed Name: Vectra AI Blog

Threat Score
75/100

Date Published: 2023-11-06

Date Updated: 2026-05-01

...
...

On May 23, 2023 Barracuda disclosed CVE-2023-2868 affecting its Email Security Gateway; attackers were exploiting it in the wild. The report dissects a Rapid7 PoC that crafts a malformed TAR archive (splitting a long filename/command across headers) to evade a Suricata Emerging Threats rule looking for paired backtick/single-quote sequences. The authors identified the detection gap, rewrote and submitted an improved M2 detection rule (SID 2048146 rev 2), and provide recommendations to ensure updated rulesets are deployed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.