CRITICAL

CVE-2021-27877

Veritas Backup Exec 2021-03-01 CVSS v3.1
CVSS
9.8
KEV

Description

An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authentication is one of these. This authentication scheme is no longer used in current versions of the product, but hadn't yet been disabled. An attacker could remotely exploit this scheme to gain unauthorized access to an Agent and execute privileged commands.

Summary dbcve.org

Veritas Backup Exec before version 21.2 contained a deprecated SHA authentication scheme that remained enabled despite being discontinued. Attackers could remotely exploit this forgotten authentication mechanism to bypass access controls, gain unauthorized Agent access, and execute privileged commands with elevated system privileges.

Mitigation

Upgrade Veritas Backup Exec to version 21.2 or later, which disables the deprecated SHA authentication scheme. If immediate upgrade is not feasible, network segmentation and restricting agent communication ports may reduce attack surface.

Proof of Concept

EPSS Score

64.91%
Probability of exploitation in next 30 days
99.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE