PT-2021-7747 · Veritas · Veritas Backup Exec
CVE-2021-27877
·
Published
2021-03-01
·
Updated
2026-07-05
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Veritas Backup Exec versions prior to 21.2
Description
An authentication flaw exists due to the continued support of the SHA cryptographic algorithm authentication scheme. Although this scheme is no longer used in current versions, it remained enabled, allowing a remote attacker to bypass security restrictions, gain unauthorized access to an Agent, and execute privileged commands.
Recommendations
Update to version 21.2 or later.
Exploit
Fix
RCE
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Veritas Backup Exec