veritas Vulnerabilities and Affected Products
Vulnerabilities associated with Backup Exec Agent.
Products
Clear product- enterprise_vault8 vulnerabilities
- Backup Exec Agent5 vulnerabilities
- netbackup3 vulnerabilities
- backup_exec2 vulnerabilities
- Data Insight2 vulnerabilities
- ediscovery_platform1 vulnerability
- system_recovery1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2021-27877HIGH | Veritas Backup Exec Agent Improper Authentication VulnerabilityAn issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authentication is one of these. This authentication scheme is no longer used in current versions of the product, but hadn't yet been disabled. An attacker could remotely exploit this scheme to gain unauthorized access to an Agent and execute privileged commands. | CVSS8.2v3.1 | EPSS64.9% | PoCs2 | SignalsListed in CISA KEVKnown ransomware use1 Nuclei template | STIX |
CVE-2021-27878HIGH | Veritas Backup Exec Agent Command Execution VulnerabilityAn issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a secure TLS communication. However, due to a vulnerability in the SHA Authentication scheme, an attacker is able to gain unauthorized access and complete the authentication process. Subsequently, the client can execute data management protocol commands on the authenticated connection. The attacker could use one of these… CWE-287Mar 1, 2021 | CVSS8.8v3.1 | EPSS24% | PoCs1 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2021-27876HIGH | Veritas Backup Exec Agent File Access VulnerabilityAn issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a secure TLS communication. However, due to a vulnerability in the SHA Authentication scheme, an attacker is able to gain unauthorized access and complete the authentication process. Subsequently, the client can execute data management protocol commands on the authenticated connection. By using crafted input parameters i… CWE-287Mar 1, 2021 | CVSS8.1v3.1 | EPSS13.5% | PoCs2 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
VERITAS Backup Exec NDMP Agent Hardcoded PasswordVERITAS Backup Exec for Windows Servers 8.6 through 10.0, Backup Exec for NetWare Servers 9.0 and 9.1, and NetBackup for NetWare Media Server Option 4.5 through 5.1 uses a static password during authentication from the NDMP agent to the server, which allows remote attackers to read and write arbitrary files with the backup server. Aug 17, 2005 | CVSS10.0v2.0 | EPSS87% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Veritas Backup Exec Agent Out-of-bounds WriteStack-based buffer overflow in VERITAS Backup Exec Remote Agent 9.0 through 10.0 for Windows, and 9.0.4019 through 9.1.307 for Netware allows remote attackers to execute arbitrary code via a CONNECT_CLIENT_AUTH request with authentication method type 3 (Windows credentials) and a long password argument. Jun 29, 2005 | CVSS7.5v2.0 | EPSS86.4% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |