Executive brief
Veritas Backup Exec Agent contains a file access vulnerability due to a flaw in the SHA Authentication scheme. An attacker can bypass authentication to execute data management protocol commands with System privileges, allowing unauthorized access to arbitrary files on the host machine.
Affected products
- Veritas Backup Exec before 21.2
Timeline
- 2021-03-01: disclosed: NVD Published Date
- 2023-04-07: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-04-28: other: Due date for remediation per CISA KEV catalog