CVE-2010-20109 describes a path traversal vulnerability in the view_help.cgi endpoint of Barracuda Spam & Virus Firewall, SSL VPN, and Web Application Firewall products prior to October 2010. The flaw allows unauthenticated remote attackers to access arbitrary files, such as sensitive configuration data, due to improper sanitization of the 'locale' parameter. This vulnerability carries a high CVSS score of 8.7, indicating a critical risk with a network attack vector and no user interaction required, potentially leading to the exposure of credentials and internal settings. While not listed in CISA's KEV catalog, a Metasploit module exists for exploitation, and the vulnerability has garnered significant community discussion, suggesting active awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Barracuda Networks | SSL VPN | >= 0, <= 2010-10CNA affecteddefault unaffected | |
| Barracuda Networks | Spam & Virus Firewall | >= 0, <= 4.1.1.021CNA affecteddefault unaffected | |
| Barracuda Networks | Web Application Firewall | >= 0, <= 2010-10CNA affecteddefault unknown |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.