Barracuda Urges customers to replace hacked ESG Appliance


Userlevel 7
Badge +9

In line with the breach reported by @dips 12 days ago, Barracuda is urging their customers that were impacted by the zero day flaw in its Email Security Gateway (ESG) to replace them forthwith.

To learn about the initial compromise, please take a look at the link attached below.

​​​​"Impacted ESG appliances must be immediately replaced regardless of patch version level," the company said in an update, adding its "remediation recommendation at this time is full replacement of the impacted ESG."

For more information, kindly take a look at this link: https://vulnera.com/newswire/barracuda-urges-immediate-replacement-of-hacked-esg-appliances/


4 comments

Userlevel 7
Badge +20

Wow entire replacement sheesh.  😐

Userlevel 7
Badge +9

Wow entire replacement sheesh.  😐

It seems the patch was not effective against the persistent and easy remote access to the appliance!

Userlevel 7
Badge +20

Wow entire replacement sheesh.  😐

It seems the patch was not effective against the persistent and easy remote access to the appliance!

Well at least there is a fix albeit a more expensive one.  😂

They should replace them for free for customers. 😉

Userlevel 7
Badge +6

I saw something about this last week.  Many of my clients are using Barracuda Email Gateway Defense (formerly ESS) for a cloud-based messaging hygiene.  I can’t imagine there are that many folks still utilizing an email security gateway on-premise.  Makes me glad we don’t have those appliances on premise, but does make me wonder about those clients of mine using other Barracuda appliances on premise such as email archiving or even their NextGen/CloudGen Firewalls.

Comment