ZeroHour

CVE-2021-27877

KEV ransomware PoC large1

Unauthenticated RCE in Veritas Backup Exec Agent via Legacy SHA Authentication

CISA: Veritas Backup Exec Agent Improper Authentication Vulnerability

CVSS 3.1
9.8 critical
EPSS
65%p99
Published
()
KEV added
AI analysis

Veritas Backup Exec Agent — the remote agent component of Veritas Backup Exec — still accepts a legacy 'SHA' authentication scheme that current versions no longer use but had never disabled, an improper authentication flaw tracked as CVE-2021-27877. Because the obsolete scheme remains enabled, a remote, unauthenticated attacker can authenticate to the Agent's network service and issue privileged commands, effectively achieving remote code execution on the host (CVSS 3.1: 9.8, Critical). Any Backup Exec deployment running a version before 21.2 is affected wherever the Agent service is reachable — either exposed to the internet or reachable inside the network after an initial compromise. A public proof-of-concept remote code execution exploit is available, and the flaw carries a very high near-term exploitation likelihood (EPSS ~65%). The bug is actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-04-07 with known ransomware use, and the ALPHV/BlackCat ransomware affiliate has been reported targeting Veritas Backup Exec flaws.

What to do: Upgrade Veritas Backup Exec to 21.2 or later per vendor instructions, as required by CISA's Known Exploited Vulnerabilities catalog. As an interim mitigation, restrict the Backup Exec Agent service (TCP/10000) to trusted backup servers and block it from untrusted networks, including the internet. Given confirmed ransomware use by ALPHV/BlackCat, prioritize patching internet-exposed and high-value backup servers.

Affected
Veritas Backup Exec (Agent component)all versions before 21.2 (fixed in 21.2)
Veritas Backup Exec Agentas shipped with Backup Exec before 21.2
Estimated exposure
large≈ tens of thousands of internet-exposed Backup Exec Agent hosts (order of 10⁴), within a plausibly 100,000+ deployment installed base (estimate) — Backup Exec is a long-standing, widely deployed mid-market backup product, and public internet scans of its Agent service (TCP/10000) have historically shown on the order of tens of thousands of exposed hosts; most Agents sit on internal…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authentication is one of these. This authentication scheme is no longer used in current versions of the product, but hadn't yet been disabled. An attacker could remotely exploit this scheme to gain unauthorized access to an Agent and execute privileged commands.

CISA Known Exploited Vulnerability
Affected
Veritas Backup Exec Agent
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
veritas
Products
backup exec
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news