CVE-2014-2595
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 17%
exploitation probability
17%top 3% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a permanent authentication token obtained from a query string.
Affected products
n/a · n/apublic PoCs found — 2
cve_referencepacketstormsecurity.com/files/127740/Barracuda-WAF-Authentication-Bypass.htmlunverifiedcve_referencewww.exploit-db.com/exploits/39278unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/127740/Barracuda-WAF-Authentication-Bypass.htmlhttp://seclists.org/fulldisclosure/2014/Aug/5https://vulners.com/securityvulns/SECURITYVULNS:DOC:31004https://www.exploit-db.com/exploits/39278https://www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2014-2595/https://www.securityfocus.com/bid/69028http://www.osvdb.org/109782