TROYANOSYVIRUS
Voltar para CVEs

CVE-2021-27877

HIGHCISA KEV
8.2

Descricao

An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authentication is one of these. This authentication scheme is no longer used in current versions of the product, but hadn't yet been disabled. An attacker could remotely exploit this scheme to gain unauthorized access to an Agent and execute privileged commands.

Detalhes CVE

Pontuacao CVSS v3.18.2
SeveridadeHIGH
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioNONE
Publicado3/1/2021
Ultima modificacao11/3/2025
Fontekev
Avistamentos honeypot0

CISA KEV

FornecedorVeritas
ProdutoBackup Exec Agent
Nome da vulnerabilidadeVeritas Backup Exec Agent Improper Authentication Vulnerability
Data inclusao KEV2023-04-07
Prazo de remediacao2023-04-28
Uso em ransomwareKnown

Produtos afetados

veritas:backup_exec

Correlacoes IOC

Sem correlacoes registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.