|
|
|
![]() |
Vulnerability Note VU#199348Barracuda Spam Firewall contains hardcoded default login credentialsOverviewBarracuda Spam Firewalls from version 3.3.01.001 to 3.3.02.053 have default login credentials that can not be modified by an administrator.I. DescriptionBarracuda Spam Firewall appliances provide ingress and egress spam filtering for local area networks. An administrator will typically log into the device by supplying credentials to a secure web-interface.Barracuda Spam Firewalls version 3.3.01.001 to 3.3.02.053 have a guest account with a fixed username and password. This account can log in to the web interface and can not be restricted by the system's built-in access control lists.
Barracuda has published updates that address this issue. Refer to the systems affected portion of this document for more details.
References
Thanks to Greg Sinclair for reporting this vulnerability. This document was written by Ryan Giobbi.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||