Skip to content
COOEY

EXPOSURES › CVE-2021-27877

CVE-2021-27877

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-04-07 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-27877 ↗
⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwareexploited-in-wildunpatched

Veritas Backup Exec Agent's improper authentication flaw allowed unauthorized access via SHA, enabling ransomware attacks.

The Veritas Backup Exec Agent suffered an improper authentication vulnerability that allowed attackers to bypass authentication using the SHA scheme, granting unauthorized access to the agent. This failure is critical for DIB organizations because backup systems are high-value targets for ransomware, and compromised backup agents can lead to data encryption and loss. Organizations must ensure all backup software is patched and monitored for exploitation, especially those listed in CISA's KEV catalog.

Shame score — The vulnerability was actively exploited in the wild and linked to ransomware, indicating a severe, avoidable failure in authentication design and patch management.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Veritas Backup Exec (BE) Agent contains an improper authentication vulnerability that could allow an attacker unauthorized access to the BE Agent via SHA authentication scheme.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.