First published: Mon Mar 01 2021(Updated: )
An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authentication is one of these. This authentication scheme is no longer used in current versions of the product, but hadn't yet been disabled. An attacker could remotely exploit this scheme to gain unauthorized access to an Agent and execute privileged commands.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Veritas Backup Exec | <21.2 | |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27877 has been classified with medium severity due to its potential for remote code execution.
To remediate CVE-2021-27877, upgrade Veritas Backup Exec to version 21.2 or a later version.
CVE-2021-27877 affects users of Veritas Backup Exec versions prior to 21.2 that still utilize the SHA authentication scheme.
CVE-2021-27877 is a remote code execution vulnerability related to outdated authentication support.
Yes, there are known exploits for CVE-2021-27877 that take advantage of the vulnerable SHA authentication scheme.