KEVIntel
8.2
CVSS
High

CVE-2021-27877

PUBLISHED

An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authentication is one of these. This...

Exploited in the wild Used in malware Remote Low complexity No user interaction
Vendor
Veritas
Product
Backup Exec
Published
Mar 01, 2021
EPSS

Description

An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authentication is one of these. This authentication scheme is no longer used in current versions of the product, but hadn't yet been disabled. An attacker could remotely exploit this scheme to gain unauthorized access to an Agent and execute privileged commands.

cisa malware ransomware nuclei_scanner metasploit

CVSS scores

CVSS v3.1 8.2 High

CVSS:3.1/AC:L/AV:N/A:N/C:H/I:L/PR:N/S:U/UI:N

Exploitation status

Exploited in the wild

Recorded 2023-04-07 00:00:00 UTC · Source

Used in malware

Recorded 2023-04-07 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
Yes
Technical impact
partial

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Apr 07, 2023

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Exploit Used in Malware

  • Added to KEVIntel

  • Detected by Metasploit

  • Detected by Nuclei