Executive brief
Veritas Backup Exec Agent contains a vulnerability in its SHA Authentication scheme that allows an attacker to bypass authentication. Once authenticated, an attacker can use data management protocol commands to execute arbitrary commands with system privileges on the target machine.
Affected products
- Veritas Backup Exec Agent before 21.2
Timeline
- 2021-03-01: disclosed: NVD Published Date
- 2021-03-08: patched: NIST initial analysis and vendor advisory reference
- 2023-04-07: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-04-07: exploited: Reported as exploited in the wild per CISA KEV entry