Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-27877 PoC — Veritas Backup Exec 安全漏洞

Source
Associated Vulnerability
Title:Veritas Backup Exec 安全漏洞 (CVE-2021-27877)
Description:Veritas Technologies Veritas Backup Exec是美国Veritas Technologies公司的一套功能强大的数据备份恢复工具。该软件拥有基于web的管理控制台和带有易用向导的直观图形用户界面,可以简化安装过程,提高可管理性。高性能代理和选件,具有快速保护台式电脑、笔记本电脑和服务器数据的灵活性。可以为Microsoft Windows服务器环境提供经过认证的、全面的、经济高效的保护。 Veritas Backup Exec before 21.2 存在安全漏洞,攻击者
Description
An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes- SHA authentication is one of these. This authentication scheme is no longer used in current versions of the product, but hadn't yet been disabled. An attacker could remotely exploit this scheme to gain unauthorized access to an Agent and execute privileged commands.
File Snapshot

id: CVE-2021-27877 info: name: Veritas Backup Exec - Broken Authentication author: pussycat0x,D ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.