Junglewise Threat Intelligence

CVE-2021-27878: Veritas Backup Exec Agent Command Execution Vulnerability

CVE-2021-27878 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2023-04-07

Technologies: Veritas Backup Exec Agent. Vendors: Veritas.

Executive brief

Veritas Backup Exec Agent contains a vulnerability in its SHA Authentication scheme that allows an attacker to bypass authentication. Once authenticated, an attacker can use data management protocol commands to execute arbitrary commands with system privileges on the target machine.

Affected products

  • Veritas Backup Exec Agent before 21.2

Timeline

  • 2021-03-01: disclosed: NVD Published Date
  • 2021-03-08: patched: NIST initial analysis and vendor advisory reference
  • 2023-04-07: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-04-07: exploited: Reported as exploited in the wild per CISA KEV entry

Related threats