Vulnerabilities > Barracuda > Load Balancer ADC

DATE CVE VULNERABILITY TITLE RISK
2020-03-12 CVE-2019-5648 Insufficiently Protected Credentials vulnerability in Barracuda Load Balancer ADC Firmware
Authenticated, administrative access to a Barracuda Load Balancer ADC running unpatched firmware <= v6.4 allows one to edit the LDAP service configuration of the balancer and change the LDAP server to an attacker-controlled system, without having to re-enter LDAP credentials.
network
low complexity
barracuda CWE-522
5.5
2017-07-18 CVE-2017-6320 OS Command Injection vulnerability in Barracuda Load Balancer ADC
A remote command injection vulnerability exists in the Barracuda Load Balancer product line (confirmed on v5.4.0.004 (2015-11-26) and v6.0.1.006 (2016-08-19); fixed in 6.1.0.003 (2017-01-17)) in which an authenticated user can execute arbitrary shell commands and gain root privileges.
network
low complexity
barracuda CWE-78
critical
9.0