Skip to content
COOEY

EXPOSURES › CVE-2021-27876

CVE-2021-27876

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-04-07 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-27876 ↗
⌖ EXPLOITED IN THE WILD SHAME 78/100 ransomwareexploited-in-wildunpatched

Veritas Backup Exec Agent allows attackers to access local files via crafted data management protocol commands.

An unpatched file access vulnerability in Veritas Backup Exec Agent lets attackers read arbitrary files on the host, exposing sensitive data and enabling further compromise. DIB organizations must ensure all backup agents are patched and monitored, as this flaw was actively exploited in the wild and linked to ransomware campaigns.

Shame score — A known, actively exploited file access vulnerability in critical backup infrastructure that was left unpatched and linked to ransomware, demonstrating severe negligence.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Veritas Backup Exec (BE) Agent contains a file access vulnerability that could allow an attacker to specially craft input parameters on a data management protocol command to access files on the BE Agent machine.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.