← Vulnerability feed

Vulnerability record · CVE-2021-27878 · published 1 March 2021

CVE-2021-27878: Veritas Backup Exec Agent SHA authentication bypass leading to command execution

VVeritas · Backup Exec

Veritas Backup Exec before 21.2 contains a flaw in the SHA authentication scheme used between client and Agent. An attacker can bypass authentication and then issue data management protocol commands on the authenticated connection. Because one of those commands allows arbitrary command execution with system privileges, the flaw is a full compromise path on affected installations.

8.8 CVSS 3.1 High CISA KEV since 7 Apr 2023 Known ransomware use EPSS 24% · top 2.2%
8.8CVSS 3.1 base score, v2 9.0
24%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a secure TLS communication. However, due to a vulnerability in the SHA Authentication scheme, an attacker is able to gain unauthorized access and complete the authentication process. Subsequently, the client can execute data management protocol commands on the authenticated connection. The attacker could use one of these commands to execute an arbitrary command on the system using system privileges.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityRemote authentication bypass leading to system-level command execution, listed in CISA KEV with known ransomware use and a high EPSS score.

What it is

Veritas Backup Exec before 21.2 contains a flaw in the SHA authentication scheme used between client and Agent. An attacker can bypass authentication and then issue data management protocol commands on the authenticated connection. Because one of those commands allows arbitrary command execution with system privileges, the flaw is a full compromise path on affected installations.

Impact

An attacker gains authenticated access to the Backup Exec Agent and can execute arbitrary commands with system privileges, effectively taking over the host. This can lead to data theft, ransomware deployment, or further lateral movement.

Attack surface

Reachable over the network via the client-to-Agent communication channel (CVSS AV:N). The vector indicates low privileges (PR:L) and no user interaction (UI:N), so the attacker needs some initial access or credentials but not administrative rights.

Exploitation

Listed in CISA KEV with known ransomware campaign use, and a public exploit reference exists on Packet Storm. EPSS is 0.23952 (97.7th percentile), indicating high likelihood of exploitation activity.

What to do

  • Upgrade Veritas Backup Exec to version 21.2 or later per vendor advisory VTS21-001.
  • Restrict network access to Backup Exec Agent ports to trusted management hosts only.
  • Rotate credentials and review accounts that can reach the Agent service.
  • Monitor for unexpected command execution or data management protocol activity from Agent connections.
  • Apply CISA KEV required actions and track remediation by the 2023-04-28 due date if still outstanding.

Detection

  • Alert on Backup Exec Agent authentication events that succeed without expected TLS client identity or from unusual source hosts.
  • Hunt for child processes spawned by the Backup Exec Agent service, especially command interpreters or scripting engines.
  • Monitor network traffic to Agent ports for anomalous data management protocol commands.
  • Correlate Backup Exec Agent activity with ransomware precursor behaviors such as credential dumping or lateral movement.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-27878 to the Known Exploited Vulnerabilities catalog on 7 April 2023 as "Veritas Backup Exec Agent Command Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 28 April 2023.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-27878 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-27877Veritas Backup Exec Agent improper authentication via legacy SHA schemeVeritas Backup Exec before 21.2 still supported a legacy SHA authentication scheme that should have been disabled. Because that scheme is weak, an un…KEVEPSS 65%analysed8.1CVE-2021-27876Veritas Backup Exec Agent authentication bypass enabling arbitrary file accessVeritas Backup Exec before 21.2 has a flaw in the SHA authentication scheme used between client and Agent. An attacker can bypass authentication and …KEVEPSS 14%analysed9.8CVE-2017-8895Veritas Backup Exec agents use-after-free allows remote code executionVeritas Backup Exec 2014, 15 and 16 contain a use-after-free flaw in multiple agents. An unauthenticated attacker can crash the agent or potentially …EPSS 71%analysed8.8CVE-2020-36167Veritas backup exec unrestricted file upload vulnerabilityAn issue was discovered in the server in Veritas Backup Exec through 16.2, 20.6 before hotfix 298543, and 21.1 before hotfix 657517. On start-up, it …EPSS 0.46%7.8CVE-2024-33673Veritas backup exec improper access control vulnerabilityAn issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. Improper access controls allow for DLL Hijacking in the Windows DLL Search …EPSS 0.16%7.5CVE-2005-0772Veritas backup exec null pointer dereference vulnerabilityVERITAS Backup Exec 9.0 through 10.0 for Windows Servers, and 9.0.4019 through 9.1.307 for Netware, allows remote attackers to cause a denial of serv…EPSS 36%7.1CVE-2024-33671Veritas backup exec vulnerabilityAn issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. The Backup Exec Deduplication Multi-threaded Streaming Agent can be leverag…EPSS 0.17%

Source: NIST National Vulnerability Database (record CVE-2021-27878), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.