Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. Barracuda/
  3. Barracuda Network Protection

Barracuda Network Protection

FirewallAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 40 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~46 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

Network and firewall protection.

by Barracuda · barracuda.com · source ↗

Known CVEs (40)About this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2026-43487 ↗MEDIUM 5.52026

    In the Linux kernel, the following vulnerability has been resolved: ata: libata-core: Disable LPM on ST1000DM010-2EP102 According to a user report, the ST1000DM010-2EP102 has problems with LPM, caus…

  • CVE-2026-22676 ↗HIGH 7.82026

    Barracuda RMM versions prior to 2025.2.2 contain a privilege escalation vulnerability that allows local attackers to gain SYSTEM-level privileges by exploiting overly permissive filesystem ACLs on the…

  • CVE-2025-34395 ↗HIGH 7.52025

    Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, exposes a .NET Remoting service in which an unauthenticated attacker can invoke a method vulnerable to path…

  • CVE-2025-34394 ↗CRITICAL 9.82025

    Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, exposes a .NET Remoting service that is insufficiently protected against deserialization of arbitrary types…

  • CVE-2025-34393 ↗CRITICAL 9.82025

    Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not correctly verify the name of an attacker-controlled WSDL service, leading to insecure reflection. …

  • CVE-2025-34392 ↗CRITICAL 9.82025

    Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not verify the URL defined in an attacker-controlled WSDL that is later loaded by the application. Thi…

  • CVE-2010-20109 ↗2025

    Barracuda products, confirmed in Spam & Virus Firewall, SSL VPN, and Web Application Firewall versions prior to October 2010, contain a path traversal vulnerability in the view_help.cgi endpoint. The …

  • CVE-2023-7102 ↗CRITICAL 9.82023

    Use of a Third Party library produced a vulnerability in Barracuda Networks Inc. Barracuda ESG Appliance which allowed Parameter Injection.This issue affected Barracuda ESG Appliance, from 5.1.3.001 t…

  • CVE-2023-2868 ↗⚠ actively exploitedCRITICAL 9.42023

    A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.001-9.2.0.006. The vulnerability arises out of a f…

  • CVE-2023-26213 ↗HIGH 7.22023

    On Barracuda CloudGen WAN Private Edge Gateway devices before 8 webui-sdwan-1089-8.3.1-174141891, an OS command injection vulnerability exists in /ajax/update_certificate - a crafted HTTP request allo…

  • CVE-2021-42711 ↗HIGH 7.82021

    Barracuda Network Access Client before 5.2.2 creates a Temporary File in a Directory with Insecure Permissions. This file is executed with SYSTEM privileges when an unprivileged user performs a repair…

  • CVE-2019-5648 ↗MEDIUM 6.52020

    Authenticated, administrative access to a Barracuda Load Balancer ADC running unpatched firmware <= v6.4 allows one to edit the LDAP service configuration of the balancer and change the LDAP server to…

  • CVE-2014-2595 ↗CRITICAL 9.82020

    Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a permanent authentication token obtained from a query string.

  • CVE-2019-6724 ↗HIGH 7.82019

    The barracudavpn component of the Barracuda VPN Client prior to version 5.0.2.7 for Linux, macOS, and OpenBSD runs as a privileged process and can allow an unprivileged local attacker to load a malici…

  • CVE-2018-20369 ↗MEDIUM 6.12018

    Barracuda Message Archiver 2018 has XSS in the error_msg exception-handling value for the ldap_user parameter to the cgi-mod/ldap_load_entry.cgi module. The injection point of the issue is the Add_Upd…

  • CVE-2014-8428 ↗CRITICAL 9.82017

    Privilege escalation vulnerability in Barracuda Load Balancer 5.0.0.015 via the use of an improperly protected SSH key.

  • CVE-2014-8426 ↗CRITICAL 9.82017

    Hard coded weak credentials in Barracuda Load Balancer 5.0.0.015.

  • CVE-2017-6320 ↗HIGH 8.82017

    A remote command injection vulnerability exists in the Barracuda Load Balancer product line (confirmed on v5.4.0.004 (2015-11-26) and v6.0.1.006 (2016-08-19); fixed in 6.1.0.003 (2017-01-17)) in which…

  • CVE-2015-0962 ↗MEDIUM 4.32015

    Barracuda Web Filter 7.x and 8.x before 8.1.0.005, when SSL Inspection is enabled, uses the same root Certification Authority certificate across different customers' installations, which makes it easi…

  • CVE-2015-0961 ↗MEDIUM 4.32015

    Barracuda Web Filter before 8.1.0.005, when SSL Inspection is enabled, does not verify X.509 certificates from upstream SSL servers, which allows man-in-the-middle attackers to spoof servers and obtai…

  • …and 20 more

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other Network Firewall (NGFW) products

see all →
  • AhnLab Network PLUS · AhnLab
  • Akamai Guardicore Segmentation · Akamai
  • Albarius · Albarius
  • AlgoSec AlgoBot · AlgoSec
  • AlgoSec Firewall Analyzer · AlgoSec
  • Allot Secure · Allot
  • Array ASI SSL Intercept · Array Networks
  • BeBroadband Application Awareness Security · BBT.live (BeBroadband)