CVE-2021-27877
Description
An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authentication is one of these. This authentication scheme is no longer used in current versions of the product, but hadn't yet been disabled. An attacker could remotely exploit this scheme to gain unauthorized access to an Agent and execute privileged commands.
Summary dbcve.org
Veritas Backup Exec before version 21.2 contained a deprecated SHA authentication scheme that remained enabled despite being discontinued. Attackers could remotely exploit this forgotten authentication mechanism to bypass access controls, gain unauthorized Agent access, and execute privileged commands with elevated system privileges.
Mitigation
Upgrade Veritas Backup Exec to version 21.2 or later, which disables the deprecated SHA authentication scheme. If immediate upgrade is not feasible, network segmentation and restricting agent communication ports may reduce attack surface.