Barracuda Appliances Have Exploitable Holes, Fixed By Firmware Updates 88
Orome1 writes "Barracuda Networks has released firmware updates that remove SSH backdoors in a number of their products and resolve a vulnerability in Barracuda SSL VPN that allows attackers to bypass access restrictions to download potentially insecure files, set new admins passwords, or even shut down the device. The backdoor accounts are present on in all available versions of Barracuda Spam and Virus Firewall, Web Filter, Message Archiver, Web Application Firewall, Link Balancer, Load Balancer, and SSL VPN appliances." Here's Barracuda's tech note about the exploitable holes.
Original source for Advisory (Score:5, Informative)
SEC Consult Vulnerability Lab Security Advisory - 20130124-0 [sec-consult.com]
title: Critical SSH Backdoor in multiple Barracuda Networks Products
vulnerable products: Barracuda Spam and Virus Firewall
Barracuda Web Filter
Barracuda Message Archiver
Barracuda Web Application Firewall
Barracuda Link Balancer
Barracuda Load Balancer
Barracuda SSL VPN
(all including their respective virtual "Vx" versions)
vulnerable version: all versions Security Definition 2.0.5
fixed version: Security Definition 2.0.5
impact: Critical
homepage: https://www.barracudanetworks.com/
found: 2012-11-20
by: S. Viehbck
SEC Consult Vulnerability Lab
https://www.sec-consult.com
Re:small set of ips (Score:3, Informative)
The blocks are:
205.158.110.0/24
216.129.105.0/24
http://cnet.robtex.com/205.158.110.html
http://cnet.robtex.com/216.129.105.html
OPENVPN (Score:4, Informative)
Live it, love it, use it (oh and it has commercial support too so it's not just a toy). http://openvpn.net/ [openvpn.net]
Re:small set of ips (Score:4, Informative)
Re:small set of ips (Score:5, Informative)
Re:A major flaw (Score:2, Informative)
What they call a "firmware update" is incorrect, from what I can tell this just patches the file that contains the allowed SSH ips and nothing more. I have one of the effected devices which does NOT have SSH enabled from outside and it downloaded and installed the "security update" on its own during its usual hourly update cycle.