Fixed in SSL VPN 2.6.0
The Barracuda SSLVPN was vulnerable to cross site request forgery attacks.The attack required a logged in administrator to click a URL crafted by an attacker in order to make a change to the system. Vulnerability is fixed in the version listed above.
To ensure maximum protection Barracuda Networks recommends that all customers upgrade to the latest generally available firmware and enable all definition updates.
Link to this page: