CVE-2021-27878
Summary
| CVE | CVE-2021-27878 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-03-01 22:15:00 UTC |
| Updated | 2022-09-27 20:15:00 UTC |
| Description | An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a secure TLS communication. However, due to a vulnerability in the SHA Authentication scheme, an attacker is able to gain unauthorized access and complete the authentication process. Subsequently, the client can execute data management protocol commands on the authenticated connection. The attacker could use one of these commands to execute an arbitrary command on the system using system privileges. |
Risk And Classification
EPSS: 0.012920000 probability, percentile 0.796210000 (date 2026-04-01)
CISA KEV: Listed on 2023-04-07; due 2023-04-28; ransomware use Known
Problem Types: CWE-287
CISA Known Exploited Vulnerability
| Vendor | Veritas |
|---|---|
| Product | Backup Exec Agent |
| Name | Veritas Backup Exec Agent Command Execution Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://www.veritas.com/support/en_US/security/VTS21-001; https://nvd.nist.gov/vuln/detail/CVE-2021-27878 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Veritas | Backup Exec | All | All | All | All |
| Application | Veritas | Backup Exec | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Veritas Backup Exec Agent Remote Code Execution ≈ Packet Storm | MISC | packetstormsecurity.com | |
| Security Advisory for Backup Exec version 21.2 | Veritas™ | MISC | www.veritas.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 378370 Veritas Backup Exec Multiple Security Vulnerabilities (VTS21-001)