Junglewise Threat Intelligence

CVE-2021-27877: Veritas Backup Exec Agent Improper Authentication Vulnerability

CVE-2021-27877 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2023-04-07

Technologies: Veritas Backup Exec Agent. Vendors: Veritas.

Executive brief

Veritas Backup Exec Agent contains an improper authentication vulnerability due to the continued support of a legacy SHA authentication scheme. Remote attackers can exploit this scheme to bypass authentication and execute privileged commands on the affected Agent.

Affected products

  • Veritas Backup Exec Agent before 21.2

Timeline

  • 2021-03-01: disclosed: NVD Published Date
  • 2023-04-07: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-03-01: patched: Fixed in version 21.2
  • 2023-04-07: exploited: Reported as exploited in the wild per CISA KEV catalog entry date

Related threats