PT-2021-7746 · Veritas · Veritas Backup Exec

Published

2021-03-01

·

Updated

2025-11-22

·

CVE-2021-27878

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Veritas Backup Exec versions prior to 21.2
Description An issue exists in Veritas Backup Exec related to flaws in the authentication procedure when using the SHA cryptographic algorithm. Exploitation may allow a remote attacker to elevate privileges and execute arbitrary commands. The communication between a client and an Agent requires successful authentication, typically completed over a secure TLS connection. However, due to a weakness in the SHA Authentication scheme, an attacker can gain unauthorized access and complete the authentication process. Subsequently, the client can execute data management protocol commands on the authenticated connection. The attacker could use these commands to execute an arbitrary command on the system using system privileges.
Recommendations Versions prior to 21.2 should be updated to version 21.2 or later.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2023-02420
CVE-2021-27878

Affected Products

Veritas Backup Exec