Barracuda fixes new ESG zero-day exploited by Chinese hackers

Zyxel says multiple NAS devices suffering from cybersecurity flaws

Cybersecurity experts at Barracuda recently discovered and patched a high-severity vulnerability in several of its email security gateway (ESG) devices.

The flaw, tracked as CVE-2023-7102, is an Arbitrary Code Execution (ACE) vulnerability found in a third-party library called Spreadsheet::ParseExcel. This library is used by the Amavis virus scanner, within the ESG device, the experts said. By creating a custom Excel attachment, the attackers could exploit the flaw and run virtually any code unabated on the vulnerable device.