← Back to browse · API

CVE-2021-27878

Severity
HIGH
CVSS
8.8
EPSS
0.23952
Risk score
68.58
CISA KEV
Yes
PoC
No
Published
2021-03-01
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2021-14616, GHSA-6R93-82VQ-9W4W
Products
Veritas:Backup Exec Agent, n/a:n/a n/a
Sources
cisa.gov CVE-2021-27878
euvd EUVD-2021-14616

Description

An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a secure TLS communication. However, due to a vulnerability in the SHA Authentication scheme, an attacker is able to gain unauthorized access and complete the authentication process. Subsequently, the client can execute data management protocol commands on the authenticated connection. The attacker could use one of these commands to execute an arbitrary command on the system using system privileges.

References