CVE-2021-27878
Description
An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a secure TLS communication. However, due to a vulnerability in the SHA Authentication scheme, an attacker is able to gain unauthorized access and complete the authentication process. Subsequently, the client can execute data management protocol commands on the authenticated connection. The attacker could use one of these commands to execute an arbitrary command on the system using system privileges.
Summary dbcve.org
A pre-authentication bypass vulnerability exists in Veritas Backup Exec's SHA Authentication scheme (versions before 21.2). An unauthenticated remote attacker can exploit this flaw to successfully complete the authentication process, then leverage data management protocol commands to execute arbitrary code with SYSTEM-level privileges.
Mitigation
Upgrade to Veritas Backup Exec 21.2 or later to obtain the patched SHA Authentication implementation. Apply network segmentation to limit agent communication to trusted networks as a compensating control until the patch can be deployed.