Skip to content
COOEY

EXPOSURES › CVE-2021-27878

CVE-2021-27878

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-04-07 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-27878 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwarerceexploited-in-wildunpatched

Veritas Backup Exec Agent allows remote command execution via data management protocol commands, enabling ransomware attackers to compromise backup systems.

An attacker can execute arbitrary commands on the Veritas Backup Exec Agent machine using a data management protocol command, directly enabling ransomware deployment. DIB organizations must patch this unpatched, actively exploited vulnerability immediately to prevent backup system compromise and data loss. This is a critical, unpatched RCE that has been exploited in the wild.

Shame score — A critical, actively exploited command execution vulnerability in a backup system that ransomware actors leverage to compromise data and disrupt operations.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Veritas Backup Exec (BE) Agent contains a command execution vulnerability that could allow an attacker to use a data management protocol command to execute a command on the BE Agent machine.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.