PromptRiskDBThreat intelligence atlas

CVE-2021-27878 - Veritas Backup Exec Agent

AI Vulnerability Context

An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a secure TLS communication. However, due to a vulnerability in the SHA Authentication scheme, an attacker is able to gain unauthorized access and complete the authentication process. Subsequently, the client can execute data management pro...

Overview

A source-backed snapshot of this vulnerability.

An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a secure TLS communication. However, due to a vulnerability in the SHA Authentication scheme, an attacker is able to gain unauthorized access and complete the authentication process. Subsequently, the client can execute data management protocol commands on the authenticated connection. The attacker could use one of these commands to execute an arbitrary command on the system using system privileges.

CISA KEVyesWhether CISA lists this as exploited.
Techniques0AI attack methods connected to this vulnerability.
Case studies0Examples where this vulnerability is mentioned.

Vulnerability status

How serious this vulnerability is and whether it is known to be exploited.

CISA KEVHIGH
CVE ID
CVE-2021-27878
Vendor/project
Veritas
Product
Backup Exec Agent
Vulnerability name
Veritas Backup Exec Agent Command Execution Vulnerability
Date added
2023-04-07
Due date
2023-04-28
Known ransomware campaign use
Known
CVSS v3
8.8
CWE-287

Exploit context

What the vulnerability is about.

An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a secure TLS communication. However, due to a vulnerability in the SHA Authentication scheme, an attacker is able to gain unauthorized access and complete the authentication process. Subsequently, the client can execute data management protocol commands on the authenticated connection. The attacker could use one of these commands to execute an arbitrary command on the system using system privileges.

Source evidence

Original public records and references for this page.

Original source

Original source links

Open the public records and source datasets used for this page.