9
CVSSv2

CVE-2017-6320

Published: 18/07/2017 Updated: 01/07/2020
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 905
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

A remote command injection vulnerability exists in the Barracuda Load Balancer product line (confirmed on v5.4.0.004 (2015-11-26) and v6.0.1.006 (2016-08-19); fixed in 6.1.0.003 (2017-01-17)) in which an authenticated user can execute arbitrary shell commands and gain root privileges. The vulnerability stems from unsanitized data being processed in a system call when the delete_assessment command is issued.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

barracuda load balancer adc

Exploits

# Exploit Title: Barracuda Load Balancer Firmware <= v601006 (2016-08-19) PostAuth remote root exploit # # Date: 01/06/2017 (Originally discovered: 3/16) # Exploit Author: xort # Software Link: wwwbarracudacom/products/loadbalancer # Version: Firmware <= v601006 (2016-08-19) # Tested on: 601006 (2016-08-19) # 6 ...
Barracuda Load Balancer Firmware versions 601006 (2016-08-19) and below post-authentication remote root exploit ...