FAIL › dossier
Veritas
VENDOR· dossier confidence 50%
Veritas is a data management vendor with a concerning security track record, highlighted by critical flaws in its Backup Exec Agent that allowed ransomware attackers to compromise backup systems through unauthorized access, remote code execution, and local file access.
PROFILE
CategoryData storage and backup software vendorWhat they doVeritas provides enterprise data management, storage, and backup solutions for organizations.
SECURITY POSTURE
Veritas has a poor security posture, evidenced by multiple critical vulnerabilities in its Backup Exec Agent that allowed unauthorized access, remote code execution, and local file access, all of which were exploited for ransomware attacks.
Notable failures
- CVE-2021-27877: Unauthorized access via SHA flaw enabling ransomware
- CVE-2021-27878: Remote code execution via data management protocol
- CVE-2021-27876: Local file access via crafted commands
Patterns: Critical vulnerabilities in backup software enabling ransomware attacks; Improper authentication and remote code execution in data management protocols
FAILURE HISTORY · 3
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2023-04-07 | CVE-2021-27877 | critical | Veritas Backup Exec Agent's improper authentication flaw allowed unauthorized access via SHA, enabling ransomware attacks. |
| 2023-04-07 | CVE-2021-27878 | critical | Veritas Backup Exec Agent allows remote command execution via data management protocol commands, enabling ransomware attackers to compromise backup systems. |
| 2023-04-07 | CVE-2021-27876 | critical | Veritas Backup Exec Agent allows attackers to access local files via crafted data management protocol commands. |
Open questions: What is the current patch status for CVE-2021-27877, CVE-2021-27878, and CVE-2021-27876? · Has Veritas issued any additional security advisories or patches since the 2023-04-07 disclosures?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-26 04:29:12.819421+00:00