Junglewise Threat Intelligence

CVE-2021-27876: Veritas Backup Exec Agent File Access Vulnerability

CVE-2021-27876 · Severity: critical · CVSS 8.1 · Exploited in the wild · Published 2023-04-07

Technologies: Veritas Backup Exec Agent. Vendors: Veritas.

Executive brief

Veritas Backup Exec Agent contains a file access vulnerability due to a flaw in the SHA Authentication scheme. An attacker can bypass authentication to execute data management protocol commands with System privileges, allowing unauthorized access to arbitrary files on the host machine.

Affected products

  • Veritas Backup Exec before 21.2

Timeline

  • 2021-03-01: disclosed: NVD Published Date
  • 2023-04-07: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-04-28: other: Due date for remediation per CISA KEV catalog

Related threats