NVD disclosure day

Published threat advisories for March 1, 2021

CVE advisoryKnown Exploit

CVE-2021-27877

Veritas Backup Exec Agent Remote Access Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in Veritas Backup Exec Agent's authentication scheme allows remote, unauthorized access and command execution. Affected organizations face risks of data compromise and system control. The issue stems from an older authentication method that remained enabled.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2021-27876

Veritas Backup Exec File Access Vulnerability.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in Veritas Backup Exec Agent's authentication allows unauthorized access. An attacker can then access arbitrary files with system privileges, impacting data confidentiality and integrity. The business risk involves potential data exposure or manipulation.

• CISA KEV