CVE-2014-2595: Critical severity barracuda web application firewall vulnerability
Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a permanent authentication token obtained from a query string.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2595?
The severity of CVE-2014-2595 is critical with a CVSS score of 9.8.
How can remote attackers bypass authentication in Barracuda Web Application Firewall (WAF) 7.8.1.013?
Remote attackers can bypass authentication by leveraging a permanent authentication token obtained from a query string.
What software is affected by CVE-2014-2595?
Barracuda Web Application Firewall (WAF) 7.8.1.013 is affected by CVE-2014-2595.
Is there a fix available for CVE-2014-2595?
Yes, upgrading to a version of Barracuda Web Application Firewall (WAF) that is not affected by the vulnerability can fix CVE-2014-2595.
Where can I find more information about CVE-2014-2595?
You can find more information about CVE-2014-2595 at the following references: [http://packetstormsecurity.com/files/127740/Barracuda-WAF-Authentication-Bypass.html](http://packetstormsecurity.com/files/127740/Barracuda-WAF-Authentication-Bypass.html), [http://seclists.org/fulldisclosure/2014/Aug/5](http://seclists.org/fulldisclosure/2014/Aug/5), [http://www.osvdb.org/109782](http://www.osvdb.org/109782).