PromptRiskDBThreat intelligence atlas

CVE-2021-27877 - Veritas Backup Exec Agent

AI Vulnerability Context

An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authentication is one of these. This authentication scheme is no longer used in current versions of the product, but hadn't yet been disabled. An attacker could remotely exploit this scheme to gain unauthorized access to an Agent and execute privileged commands.

Overview

A source-backed snapshot of this vulnerability.

CISA KEVyesWhether CISA lists this as exploited.
Techniques0AI attack methods connected to this vulnerability.
Case studies0Examples where this vulnerability is mentioned.

Vulnerability status

How serious this vulnerability is and whether it is known to be exploited.

CISA KEVHIGH
CVE ID
CVE-2021-27877
Vendor/project
Veritas
Product
Backup Exec Agent
Vulnerability name
Veritas Backup Exec Agent Improper Authentication Vulnerability
Date added
2023-04-07
Due date
2023-04-28
Known ransomware campaign use
Known
CVSS v3
8.2
CWE-287

Exploit context

What the vulnerability is about.

No description available. The source record only contains identifiers and metadata.

Source evidence

Original public records and references for this page.

Original source

Original source links

Open the public records and source datasets used for this page.