TROYANOSYVIRUS
Voltar para CVEs

CVE-2021-27876

HIGHCISA KEV
8.1

Descricao

An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a secure TLS communication. However, due to a vulnerability in the SHA Authentication scheme, an attacker is able to gain unauthorized access and complete the authentication process. Subsequently, the client can execute data management protocol commands on the authenticated connection. By using crafted input parameters in one of these commands, an attacker can access an arbitrary file on the system using System privileges.

Detalhes CVE

Pontuacao CVSS v3.18.1
SeveridadeHIGH
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosLOW
Interacao do usuarioNONE
Publicado3/1/2021
Ultima modificacao11/3/2025
Fontekev
Avistamentos honeypot0

CISA KEV

FornecedorVeritas
ProdutoBackup Exec Agent
Nome da vulnerabilidadeVeritas Backup Exec Agent File Access Vulnerability
Data inclusao KEV2023-04-07
Prazo de remediacao2023-04-28
Uso em ransomwareKnown

Produtos afetados

veritas:backup_exec

Correlacoes IOC

Sem correlacoes registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.