LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-27877: Veritas Backup Exec Agent Improper Authentication Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 7, 2023
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Apr 28, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-27877 to its Known Exploited Vulnerabilities catalog on Apr 7, 2023, with a federal patch deadline of Apr 28, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Veritas Backup Exec (BE) Agent contains an improper authentication vulnerability that could allow an attacker unauthorized access to the BE Agent via SHA authentication scheme.

CVE-2021-27877 is an improper authentication vulnerability in the Veritas Backup Exec Agent. It can allow an attacker to gain unauthorized access to the agent by abusing the SHA authentication scheme. Because Backup Exec agents commonly sit on systems that hold or can reach backup data, successful abuse can give an adversary a foothold for further movement or data access. CISA notes that this vulnerability has been used in ransomware activity, so organizations running the agent should treat it as a priority for inventory and remediation.

Public technical detail is limited to the CWE-287 classification and the CISA description; exact affected versions, CVSS scores, and exploit mechanics must be confirmed against the vendor advisory.

How it works

The flaw belongs to the improper authentication class (CWE-287). In products that implement authentication schemes such as SHA-based methods, a weakness can let an attacker bypass or subvert the intended checks. According to the CISA summary, an attacker can obtain unauthorized access to the Veritas Backup Exec Agent specifically via the SHA authentication scheme. Once authenticated to the agent, the attacker may be able to interact with it as a legitimate client would, depending on the privileges the agent process holds and the network reachability of the service. No further exploit mechanics are provided in the available facts; defenders should treat any unauthenticated or weakly authenticated network access to the agent as potentially abusable and verify details in the vendor advisory.

Am I affected? How to find it in your systems

Veritas Backup Exec Agents typically run on servers, workstations, or other endpoints that participate in backup jobs—often Windows systems, though confirm platform support with the vendor. They listen for connections from the Backup Exec media server or related management components and may be exposed on internal networks or, less commonly, to broader segments.

If inventory is incomplete, treat any system known to run Backup Exec components as potentially in scope until verified.

How to remediate

Patch first. Apply the updates provided by Veritas for the Backup Exec Agent exactly as described in the vendor advisory and per CISA’s required action to apply updates per vendor instructions. After patching, restart the agent service if required and confirm the new version is running.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls.

These measures lower risk but do not replace the patch; schedule the official update as soon as possible.

If your data may have been exposed

Actively exploited vulnerabilities, including those with known ransomware use, can lead to unauthorized access and data compromise. If you discover evidence of exploitation or cannot rule out exposure of backup data or credentials, follow your incident response plan: isolate affected systems, preserve logs, and assess what data the agent could reach. You can also run a free exposure scan of your email addresses against known breach data to check whether related accounts appear in public breach corpora, then force password resets and enable multi-factor authentication where applicable.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedVeritas · Backup Exec Agent
WeaknessCWE-287
Added to CISA KEVApr 7, 2023
Federal patch deadlineApr 28, 2023
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities