Barracuda Networks has disclosed that a zero-day vulnerability in its Email Security Gateway (ESG) appliances had been exploited for at least seven months.
According to Barracuda’s investigators, the vulnerability CVE-2023-2868 was first exploited in October 2022 to introduce backdoors into some ESG appliances, allowing attackers to gain continued access to the devices. Barracuda’s investigations discovered that information had been stolen from some of the compromised appliances.
The security flaw was not spotted until 19 May, when suspicious traffic emanated from some ESG appliances. Cybersecurity firm Mandiant helped find the vulnerability and all ESG appliances were patched on 20th May, with attackers’ access to the compromised devices blocked on 21 May.