← Back to CVE List
Vulnerability Intelligence Report
Veritas Backup Exec Agent Improper Authentication Vulnerability

CVE-2021-27877

An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authentication is one of these. This authentication scheme is no longer used in current versions of the product, but hadn't yet been disabled. An attacker could remotely exploit this scheme to gain unauthorized access to an Agent and execute privileged commands.

CISA KEV Nuclei Template SSVC: Active Exploitation Automatable
CVSS Base Score
8.2
HIGH
Exploitability:3.9
Impact Score:4.3
EPSS Probability:64.91%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-287 ↗CWE-287 (via CISA KEV)

Affected Products & Versions

Vendor Product Affected Versions
veritas backup_exec all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
64.910%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2021-03-01T00:00:00
Published2021-03-01T21:49:36
Last Updated2025-10-21T23:25:53

LINK COPIED TO CLIPBOARD