← Back to browse · API

CVE-2021-27876

Severity
HIGH
CVSS
8.1
EPSS
0.13411
Risk score
62.09
CISA KEV
Yes
PoC
No
Published
2021-03-01
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2021-14614, GHSA-9J5V-H34P-H6G6
Products
Veritas:Backup Exec Agent, n/a:n/a n/a
Sources
cisa.gov CVE-2021-27876
euvd EUVD-2021-14614

Description

An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a secure TLS communication. However, due to a vulnerability in the SHA Authentication scheme, an attacker is able to gain unauthorized access and complete the authentication process. Subsequently, the client can execute data management protocol commands on the authenticated connection. By using crafted input parameters in one of these commands, an attacker can access an arbitrary file on the system using System privileges.

References