Vulnerability record · CVE-2021-27876 · published 1 March 2021
CVE-2021-27876: Veritas Backup Exec Agent authentication bypass enabling arbitrary file access
VVeritas · Backup Exec
Veritas Backup Exec before 21.2 has a flaw in the SHA authentication scheme used between client and Agent. An attacker can bypass authentication and then issue data management protocol commands on the authenticated connection. Crafted parameters in one of those commands allow reading an arbitrary file with System privileges.
Description
An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a secure TLS communication. However, due to a vulnerability in the SHA Authentication scheme, an attacker is able to gain unauthorized access and complete the authentication process. Subsequently, the client can execute data management protocol commands on the authenticated connection. By using crafted input parameters in one of these commands, an attacker can access an arbitrary file on the system using System privileges.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Automated analysis
high priorityNetwork-reachable authentication bypass with System-level file read, public exploit material, and CISA KEV listing with known ransomware use.
What it is
Veritas Backup Exec before 21.2 has a flaw in the SHA authentication scheme used between client and Agent. An attacker can bypass authentication and then issue data management protocol commands on the authenticated connection. Crafted parameters in one of those commands allow reading an arbitrary file with System privileges.
Impact
An attacker gains unauthorized access to the Backup Exec Agent and can read arbitrary files on the host with System privileges, exposing sensitive data and configuration. The flaw does not by itself grant write or code execution, though the referenced exploit material describes remote code execution.
Attack surface
Reached over the network via the client-to-Agent communication channel (AV:N). The vector lists PR:L, so some low-privileged access is required, and no user interaction is needed (UI:N).
Exploitation
Listed in CISA KEV with known ransomware campaign use and a due date of 2023-04-28, and EPSS 30-day probability is 0.13518 (96th percentile). References include an Exploit-tagged third-party advisory, indicating public exploit material exists.
What to do
- Upgrade Veritas Backup Exec to 21.2 or later per vendor advisory VTS21-001.
- Restrict network access to Backup Exec Agent ports to trusted management hosts only.
- Rotate credentials and review accounts that can reach the Agent service.
- Monitor for and block unauthorized client connections to the Agent.
- Apply the vendor-required action from the CISA KEV entry and track remediation to the due date.
Detection
- Alert on Backup Exec Agent authentication events that succeed from unexpected or non-management hosts.
- Monitor Agent logs for data management protocol commands with unusual file path parameters.
- Hunt for anomalous file read activity by the Backup Exec Agent service account, especially outside backup windows.
- Correlate network connections to Agent ports with known client inventory and flag outliers.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-27876 to the Known Exploited Vulnerabilities catalog on 7 April 2023 as "Veritas Backup Exec Agent File Access Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 28 April 2023.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/168506/Veritas-Backup-Exec-Agent-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.veritas.com/content/support/en_US/security/VTS21-001#issue2 | Vendor Advisory |
| http://packetstormsecurity.com/files/168506/Veritas-Backup-Exec-Agent-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.veritas.com/content/support/en_US/security/VTS21-001#issue2 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-27876 | US Government Resource |
Track CVE-2021-27876 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-27876), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.