CVE-2021-27877
Published on: 03/01/2021 12:00:00 AM UTC
Last Modified on: 09/27/2022 08:15:00 PM UTC
Certain versions of Backup Exec from Veritas contain the following vulnerability:
An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authentication is one of these. This authentication scheme is no longer used in current versions of the product, but hadn't yet been disabled. An attacker could remotely exploit this scheme to gain unauthorized access to an Agent and execute privileged commands.
- CVE-2021-27877 has been assigned by
[email protected] to track the vulnerability - currently rated as CRITICAL severity.
CVSS3 Score: 9.8 - CRITICAL
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 7.5 - HIGH
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | PARTIAL | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Veritas Backup Exec Agent Remote Code Execution ≈ Packet Storm | packetstormsecurity.com text/html |
![]() |
Security Advisory for Backup Exec version 21.2 | Veritas™ | Vendor Advisory www.veritas.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Veritas | Backup Exec | All | All | All | All |
Application | Veritas | Backup Exec | All | All | All | All |
- cpe:2.3:a:veritas:backup_exec:*:*:*:*:*:*:*:*:
- cpe:2.3:a:veritas:backup_exec:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
Severity: ??? | An issue was discovered in Veritas Backu... | CVE-2021-27877 | Link for more: alerts.remotelyrmm.com/CVE-2021-27877 | 2022-09-26 19:29:12 |