Vulnerable Systems:
* Barracuda SSL VPN
* Barracuda Web Application Firewall
* Barracuda Message Archiver
* Barracuda Web Filter
* Barracuda Link Balancer
* Barracuda Load Balancer
By default, multiple Barracuda appliances install with default user credentials (username/password combination). The devices contain a variety of accounts with easily cracked passwords. In addition, the 'remote' and 'cluster' accounts ship with SSH public keys that allow Barracuda staff, or anyone able to steal their associated private key, to authenticate to the systems. Many of the accounts offer full system access, or allow an attacker to execute privileged commands via SSH.
Disclosure Timeline:
Discovery Date :2012-11-20
Vendor Informed Date :2012-11-29
Disclosure Date :2013-01-24
Exploit Publish Date :2013-01-24
Vendor Solution Date :2013-01-24