Vulnerability record · CVE-2021-27878 · published 1 March 2021
CVE-2021-27878: Veritas Backup Exec Agent SHA authentication bypass leading to command execution
VVeritas · Backup Exec
Veritas Backup Exec before 21.2 contains a flaw in the SHA authentication scheme used between client and Agent. An attacker can bypass authentication and then issue data management protocol commands on the authenticated connection. Because one of those commands allows arbitrary command execution with system privileges, the flaw is a full compromise path on affected installations.
Description
An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a secure TLS communication. However, due to a vulnerability in the SHA Authentication scheme, an attacker is able to gain unauthorized access and complete the authentication process. Subsequently, the client can execute data management protocol commands on the authenticated connection. The attacker could use one of these commands to execute an arbitrary command on the system using system privileges.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityRemote authentication bypass leading to system-level command execution, listed in CISA KEV with known ransomware use and a high EPSS score.
What it is
Veritas Backup Exec before 21.2 contains a flaw in the SHA authentication scheme used between client and Agent. An attacker can bypass authentication and then issue data management protocol commands on the authenticated connection. Because one of those commands allows arbitrary command execution with system privileges, the flaw is a full compromise path on affected installations.
Impact
An attacker gains authenticated access to the Backup Exec Agent and can execute arbitrary commands with system privileges, effectively taking over the host. This can lead to data theft, ransomware deployment, or further lateral movement.
Attack surface
Reachable over the network via the client-to-Agent communication channel (CVSS AV:N). The vector indicates low privileges (PR:L) and no user interaction (UI:N), so the attacker needs some initial access or credentials but not administrative rights.
Exploitation
Listed in CISA KEV with known ransomware campaign use, and a public exploit reference exists on Packet Storm. EPSS is 0.23952 (97.7th percentile), indicating high likelihood of exploitation activity.
What to do
- Upgrade Veritas Backup Exec to version 21.2 or later per vendor advisory VTS21-001.
- Restrict network access to Backup Exec Agent ports to trusted management hosts only.
- Rotate credentials and review accounts that can reach the Agent service.
- Monitor for unexpected command execution or data management protocol activity from Agent connections.
- Apply CISA KEV required actions and track remediation by the 2023-04-28 due date if still outstanding.
Detection
- Alert on Backup Exec Agent authentication events that succeed without expected TLS client identity or from unusual source hosts.
- Hunt for child processes spawned by the Backup Exec Agent service, especially command interpreters or scripting engines.
- Monitor network traffic to Agent ports for anomalous data management protocol commands.
- Correlate Backup Exec Agent activity with ransomware precursor behaviors such as credential dumping or lateral movement.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-27878 to the Known Exploited Vulnerabilities catalog on 7 April 2023 as "Veritas Backup Exec Agent Command Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 28 April 2023.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/168506/Veritas-Backup-Exec-Agent-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.veritas.com/content/support/en_US/security/VTS21-001#issue3 | Vendor Advisory |
| http://packetstormsecurity.com/files/168506/Veritas-Backup-Exec-Agent-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.veritas.com/content/support/en_US/security/VTS21-001#issue3 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-27878 | US Government Resource |
Track CVE-2021-27878 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-27878), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.