Backup Exec
Vendor:
First CVE: Jun 28, 2005 · Active for 21 years
8
Total CVEs
More Total CVEs than 85% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
8.5
Avg CVSS
Higher Avg CVSS than 75% of tracked products
37.5%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Backup Exec over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 28, 2005
21 years ago
Most Recent CVE
Apr 26, 2024
819 days ago
CVE Severity & Scoring
Backup Exec8 CVEs
75%
25%
All CVEs352,231 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local3 (37.5%)
Network5 (62.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low5 (62.5%)
High0 (0.0%)
None3 (37.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-27877CRITICAL An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authentication is one of these. This authentication scheme is no longer | Mar 1, 2021 | 9.8 | 96 | YES | YES |
CVE-2021-27878HIGH An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a | Mar 1, 2021 | 8.8 | 85 | YES | YES |
CVE-2017-8895CRITICAL In Veritas Backup Exec 2014 before build 14.1.1187.1126, 15 before build 14.2.1180.3160, and 16 before FP1, there is a use-after-free vulnerability in multiple agents that can lead | May 10, 2017 | 9.8 | 85 | NO | YES |
CVE-2021-27876HIGH An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a | Mar 1, 2021 | 8.1 | 79 | YES | YES |
CVE-2005-0772HIGH VERITAS Backup Exec 9.0 through 10.0 for Windows Servers, and 9.0.4019 through 9.1.307 for Netware, allows remote attackers to cause a denial of service (Remote Agent crash) via (1 | Jun 28, 2005 | 7.5 | 35 | NO | NO |
CVE-2020-36167HIGH An issue was discovered in the server in Veritas Backup Exec through 16.2, 20.6 before hotfix 298543, and 21.1 before hotfix 657517. On start-up, it loads the OpenSSL library from | Jan 6, 2021 | 8.8 | 26 | NO | NO |
CVE-2024-33673HIGH An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. Improper access controls allow for DLL Hijacking in the Windows DLL Search path. | Apr 26, 2024 | 7.8 | 22 | NO | NO |
CVE-2024-33671HIGH An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. The Backup Exec Deduplication Multi-threaded Streaming Agent can be leveraged to perform arbitrary file de | Apr 26, 2024 | 7.1 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
3 CVEs
37.5% of CVEs· 98th percentile
Metasploit
4 CVEs
50.0% of CVEs· 98th percentile
Nuclei
1 CVE
12.5% of CVEs· 97th percentile
ExploitDB
1 CVE
12.5% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Backup Exec
Top CWEs
Versions
No cataloged versions.