Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Apr 28, 2023

CVE-2021-27878

High
EPSS 1.3%CISA KEVRansomware
Veritas/Backup Exec Agent

Description

Veritas Backup Exec (BE) Agent contains a command execution vulnerability that could allow an attacker to use a data management protocol command to execute a command on the BE Agent machine.

EPSS — Exploit Probability

1.3%

Higher than 79.5% of all CVEs

Required Action

https://www.veritas.com/support/en_US/security/VTS21-001; https://nvd.nist.gov/vuln/detail/CVE-2021-27878

Risk Assessment

HIGH
In CISA KEV
Ransomware

Details

Severity
High
EPSS
1.3%
CISA KEV
Yes
Ransomware
Known
Articles
0

Timeline

Published

Apr 7, 2023

Added to KEV

Apr 7, 2023

Remediation Due

Apr 28, 2023

Affected Product

Veritas

Backup Exec Agent

View all Veritas CVEs