Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Apr 28, 2023

CVE-2021-27877

High
EPSS 33.6%CISA KEVRansomware
Veritas/Backup Exec Agent

Description

Veritas Backup Exec (BE) Agent contains an improper authentication vulnerability that could allow an attacker unauthorized access to the BE Agent via SHA authentication scheme.

EPSS — Exploit Probability

33.6%

Higher than 96.9% of all CVEs

Required Action

https://www.veritas.com/support/en_US/security/VTS21-001; https://nvd.nist.gov/vuln/detail/CVE-2021-27877

Risk Assessment

HIGH
In CISA KEV
Ransomware

Details

Severity
High
EPSS
33.6%
CISA KEV
Yes
Ransomware
Known
Articles
0

Timeline

Published

Apr 7, 2023

Added to KEV

Apr 7, 2023

Remediation Due

Apr 28, 2023

Affected Product

Veritas

Backup Exec Agent

View all Veritas CVEs