
When configuring Barracuda Network Connector on Macintosh systems, note that DNS insertion and Up/Down commands are
mutually exclusive.
What's new with the Barracuda SSL VPN Version 2.4.0.12
Fix: Clustering on new systems [BNVS-4678]
Fix: High severity vulnerability: non-persistent XSS [BNSEC-2802 / BNVS-4542]
Fix: High severity vulnerability: persistent XSS [BNSEC-2697 / BNVS-4543]
Fix: Unknown severity vulnerability: [BNSEC-380]
Fix: Unknown severity vulnerability: [BNSEC-335]
What's new with the Barracuda SSL VPN Version 2.4.0.10
Fix: External access blocked for non SSH ports [BNVS-4152]
Fix: The most recent Scheduled Backup files are retained [BNVS-4614]
Fix: High severity vulnerability: Unauthenticated, non-persistent XSS [BNSEC-1546 / BNVS-4210]
Fix: High severity vulnerability: Unauthenticated, non-persistent XSS [BNSEC-1542 / BNVS-4211]
Fix: High severity vulnerability: Clickjacking [BNSEC-509 / BNVS-4024]
Fix: Med severity vulnerability: Cross Site Request Forgery (CSRF) [BNSEC-1247 / BNVS-4079]
Fix: Med severity vulnerability: URL Redirection [BNSEC-727 / BNVS-3665]
Fix: Low severity vulnerability: Requires a man in the middle, url redirection [BNSEC-1399 / BNVS-4147]
Fix: Low severity vulnerability: Requires authentication, non-persistent XSS [BNSEC-1239 / BNVS-4078]
Fix: Low severity vulnerability: Cross Site Request Forgery (CSRF), HTTP header injection, non-persistent X SS [BNSEC-1144 /
BNVS-4026]
What's new with the Barracuda SSL VPN Version 2.4.0.9
New Features
The Device Configuration feature allows resources and other settings configured on the Barracuda SSL VPN to be provisioned directly to
a user's device.
Improved Sharepoint functionality, including supporting Sharepoint 2013.
Policy time restrictions are more comprehensive.
Improved browser NAC checking.
Download functionality for all aspects of the system works faster and more reliably.
Increased backup and restore capabilities (from the appliance interface).
Version 2.4.0.9 Fixes:
Backups
Show All Backups option on the ADVANCED > Backups page displays all backup files on the share [BNVS-4348]
Only the requested number of SMB backups is stored [BNVS-4378]
Status of SMB backup is reported accurately [BNVS-4376]
Clustering information is excluded from backups [BNVS-4382]
Other
All Network Connector client configurations can be launched from the user interface [BNVS-4381]
Fixed Java applet signing to conform to new security in Java 1.7u45 [BNVS-4516]
This error may still appear if the SSLVPN doesn't have a valid SSL certificate installed. A valid SSL certificate will be
Note:
required for all SSL VPN devices as of the release of Java 1.7u51
Version 2.4.0.7:
Fix: Mapped drives time out according to the inactivity timeout setting under Profiles [BNVS-4337]
Fix: Attempts to access hosts not in the Web Forward Allowed Hosts list displays error message [BNVS-4319]
Fix: Can log off users with Network Connector sessions using the Sessions page [BNVS-4322]
Fix: Set limitations on IP subnet range for PPTP and IPSec [BNVS-4325]
Fix: Updated Code Signing Certificate
Fix: Vulnerability - Information Disclosure [BNSEC-1839 / BNVS-4261]
Fix: Vulnerability - Unauthenticated, XSS-Not Persistent [BNSEC-1542 / BNVS-4211]
Fix: Vulnerability - Unauthenticated, XSS-Not Persistent [BNSEC-1546 / BNVS-4210]
Fix: Vulnerability - Requires Man in the Middle, URL Redirection [BNSEC-1399 / BNVS-4147]
Fix: Vulnerability - CSRF [BNSEC-1247 / BNVS-4079]