Barracuda Networks has announced the need for a physical replacement of ESG (Email Security Gateway) devices infected with malware due to a 0-day vulnerability in the email attachment processing module. It has been reported that previously released patches are insufficient to block the issue. Details are not provided, but it is presumed that the decision to replace the equipment was made due to an attack that led to the installation of malware at a low level, and the inability to remove it by re-flashing or performing a factory reset. The equipment will be replaced free of charge, but there are no specifications regarding compensation for shipping costs and replacement work.
ESG is a hardware and software solution designed to protect enterprise email from attacks, spam, and viruses. On May 18, anomalous traffic from ESG devices was recorded, which was linked to malicious activity. Analysis revealed that the devices had been compromised using an unpatched (0-day) vulnerability (CVE-2023-28681) that allows code execution via the sending of a specially crafted email. The issue was caused by a lack of proper verification of file names within tar archives transmitted as email attachments, allowing arbitrary commands to be executed on the system with elevated privileges, bypassing sanitization when executing code through the Perl operator 'qx'.
The vulnerability is present in individually supplied ESG appliances with firmware versions 5.1.3.001 to 9.2.0.006 inclusive. Instances of vulnerability exploitation have been traced back to October 2022, and the issue remained unnoticed until May 2023. Attackers utilized the vulnerability to install several types of malware on the gateways — SALTWATER, SEASPY, and SEASIDE, which provide external access to the device (backdoor) and are used for intercepting confidential data.
The SALTWATER backdoor was disguised as the mod_udp.so module for the SMTP process bsmtpd, allowing arbitrary files to be uploaded and executed in the system, as well as proxying requests and tunneling traffic externally. serverTo gain control in the backdoor, interception of system calls send, recv, and close was used.
The malicious component SEASIDE was written in Lua and installed as a module mod_require_helo.lua for the SMTP server, responsible for tracking incoming HELO/EHLO commands and identifying requests from the controller. server and determining the parameters for launching a reverse shell.
SEASPY was an executable file for BarracudaMailService, deployed as a system service. The service utilized a PCAP-based filter to monitor traffic on ports 25 (SMTP) and 587, activating the backdoor upon detecting a packet with a specific sequence.
On May 20, Barracuda released an update addressing the vulnerability, which was deployed to all devices by May 21. On June 8, it was announced that the updates were insufficient, and users needed to physically replace the compromised devices. Users are also advised to change all access keys and credentials that intersected with Barracuda ESG, for instance, those linked to LDAP/AD and Barracuda Cloud Control. Preliminary data suggests that around 11,000 ESG devices using the Barracuda Networks Spam Firewall smtpd service, applied in Email Security Gateway, are impacted.
Source: opennet.ru
