KEVIntel
8.1
CVSS
High

CVE-2021-27876

PUBLISHED

An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication,...

Exploited in the wild Used in malware Remote Low complexity No user interaction
Vendor
Veritas
Product
Backup Exec
Published
Mar 01, 2021
EPSS

Description

An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a secure TLS communication. However, due to a vulnerability in the SHA Authentication scheme, an attacker is able to gain unauthorized access and complete the authentication process. Subsequently, the client can execute data management protocol commands on the authenticated connection. By using crafted input parameters in one of these commands, an attacker can access an arbitrary file on the system using System privileges.

cisa malware ransomware metasploit

CVSS scores

CVSS v3.1 8.1 High

CVSS:3.1/AC:L/AV:N/A:N/C:H/I:H/PR:L/S:U/UI:N

Exploitation status

Exploited in the wild

Recorded 2023-04-07 00:00:00 UTC · Source

Used in malware

Recorded 2023-04-07 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
No
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Apr 07, 2023

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Exploit Used in Malware

  • Added to KEVIntel

  • Detected by Metasploit