PT-2019-18284 · Barracuda · Barracuda Vpn Client
Published
2019-03-18
·
Updated
2020-08-24
·
CVE-2019-6724
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Barracuda VPN Client versions prior to 5.0.2.7
Description
The issue allows an unprivileged local attacker to load a malicious library, resulting in arbitrary code execution as root, due to the barracudavpn component running as a privileged process.
Recommendations
For versions prior to 5.0.2.7, update to version 5.0.2.7 or later to resolve the issue.
Exploit
Fix
Untrusted Search Path
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Barracuda Vpn Client