← Vulnerability feed

Vulnerability record · CVE-2021-27876 · published 1 March 2021

CVE-2021-27876: Veritas Backup Exec Agent authentication bypass enabling arbitrary file access

VVeritas · Backup Exec

Veritas Backup Exec before 21.2 has a flaw in the SHA authentication scheme used between client and Agent. An attacker can bypass authentication and then issue data management protocol commands on the authenticated connection. Crafted parameters in one of those commands allow reading an arbitrary file with System privileges.

8.1 CVSS 3.1 High CISA KEV since 7 Apr 2023 Known ransomware use EPSS 14% · top 3.7%
8.1CVSS 3.1 base score, v2 7.5
14%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a secure TLS communication. However, due to a vulnerability in the SHA Authentication scheme, an attacker is able to gain unauthorized access and complete the authentication process. Subsequently, the client can execute data management protocol commands on the authenticated connection. By using crafted input parameters in one of these commands, an attacker can access an arbitrary file on the system using System privileges.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityNetwork-reachable authentication bypass with System-level file read, public exploit material, and CISA KEV listing with known ransomware use.

What it is

Veritas Backup Exec before 21.2 has a flaw in the SHA authentication scheme used between client and Agent. An attacker can bypass authentication and then issue data management protocol commands on the authenticated connection. Crafted parameters in one of those commands allow reading an arbitrary file with System privileges.

Impact

An attacker gains unauthorized access to the Backup Exec Agent and can read arbitrary files on the host with System privileges, exposing sensitive data and configuration. The flaw does not by itself grant write or code execution, though the referenced exploit material describes remote code execution.

Attack surface

Reached over the network via the client-to-Agent communication channel (AV:N). The vector lists PR:L, so some low-privileged access is required, and no user interaction is needed (UI:N).

Exploitation

Listed in CISA KEV with known ransomware campaign use and a due date of 2023-04-28, and EPSS 30-day probability is 0.13518 (96th percentile). References include an Exploit-tagged third-party advisory, indicating public exploit material exists.

What to do

  • Upgrade Veritas Backup Exec to 21.2 or later per vendor advisory VTS21-001.
  • Restrict network access to Backup Exec Agent ports to trusted management hosts only.
  • Rotate credentials and review accounts that can reach the Agent service.
  • Monitor for and block unauthorized client connections to the Agent.
  • Apply the vendor-required action from the CISA KEV entry and track remediation to the due date.

Detection

  • Alert on Backup Exec Agent authentication events that succeed from unexpected or non-management hosts.
  • Monitor Agent logs for data management protocol commands with unusual file path parameters.
  • Hunt for anomalous file read activity by the Backup Exec Agent service account, especially outside backup windows.
  • Correlate network connections to Agent ports with known client inventory and flag outliers.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-27876 to the Known Exploited Vulnerabilities catalog on 7 April 2023 as "Veritas Backup Exec Agent File Access Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 28 April 2023.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-27876 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-27877Veritas Backup Exec Agent improper authentication via legacy SHA schemeVeritas Backup Exec before 21.2 still supported a legacy SHA authentication scheme that should have been disabled. Because that scheme is weak, an un…KEVEPSS 65%analysed8.8CVE-2021-27878Veritas Backup Exec Agent SHA authentication bypass leading to command executionVeritas Backup Exec before 21.2 contains a flaw in the SHA authentication scheme used between client and Agent. An attacker can bypass authentication…KEVEPSS 24%analysed9.8CVE-2017-8895Veritas Backup Exec agents use-after-free allows remote code executionVeritas Backup Exec 2014, 15 and 16 contain a use-after-free flaw in multiple agents. An unauthenticated attacker can crash the agent or potentially …EPSS 71%analysed8.8CVE-2020-36167Veritas backup exec unrestricted file upload vulnerabilityAn issue was discovered in the server in Veritas Backup Exec through 16.2, 20.6 before hotfix 298543, and 21.1 before hotfix 657517. On start-up, it …EPSS 0.46%7.8CVE-2024-33673Veritas backup exec improper access control vulnerabilityAn issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. Improper access controls allow for DLL Hijacking in the Windows DLL Search …EPSS 0.16%7.5CVE-2005-0772Veritas backup exec null pointer dereference vulnerabilityVERITAS Backup Exec 9.0 through 10.0 for Windows Servers, and 9.0.4019 through 9.1.307 for Netware, allows remote attackers to cause a denial of serv…EPSS 36%7.1CVE-2024-33671Veritas backup exec vulnerabilityAn issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. The Backup Exec Deduplication Multi-threaded Streaming Agent can be leverag…EPSS 0.17%

Source: NIST National Vulnerability Database (record CVE-2021-27876), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.