Back to Database
Status published
Critical
CVE-2014-2595
Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to...
Vulnerability Description
Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a permanent authentication token obtained from a query string.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-2595
Credits & Attribution
No credits recorded in the NVD database.
References
- http://packetstormsecurity.com/files/127740/Barracuda-WAF-Authentication-Bypass.html
- https://www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2014-2595/
- http://seclists.org/fulldisclosure/2014/Aug/5
- http://www.osvdb.org/109782
- https://vulners.com/securityvulns/SECURITYVULNS:DOC:31004
- https://www.securityfocus.com/bid/69028
- https://www.exploit-db.com/exploits/39278
More from barracuda
View All →CVE-2021-42711
Barracuda Network Access Client before 5.2.2 creates a Temporary File...
High
7.8
CVE-2019-6724
The barracudavpn component of the Barracuda VPN Client prior to...
High
7.8
CVE-2018-20369
Barracuda Message Archiver 2018 has XSS in the error_msg exception-handling...
Medium
6.1
CVE-2017-6320
A remote command injection vulnerability exists in the Barracuda Load...
High
8.8
CVE-2015-0962
Barracuda Web Filter 7.x and 8.x before 8.1.0.005, when SSL...
Medium
4.3
Affected Vendor
barracuda
View all reports →Affected Software
web application firewall
Vulnerable Versions:
7.8.1.013
Timeline
Official Publish:
February 12th, 2020
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.