CVE-2007-2361
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
30/04/2007
Last modified:
09/04/2025
Description
Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, when remote backups of restore points images are configured, uses weak permissions (world readable) for a configuration file with network share credentials, which allows local users to obtain the credentials by reading the file.
Impact
Base Score 2.0
4.90
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:symantec:backupexec_system_recovery:6.5:*:*:*:*:*:*:* | ||
cpe:2.3:a:symantec:backupexec_system_recovery:6.52:*:*:*:*:*:*:* | ||
cpe:2.3:a:symantec:backupexec_system_recovery:6.52a:*:*:*:*:*:*:* | ||
cpe:2.3:a:symantec:backupexec_system_recovery:6.53:*:*:*:*:*:*:* | ||
cpe:2.3:a:symantec:livestate_recovery:6.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:symantec:livestate_recovery:6.01:*:*:*:*:*:*:* | ||
cpe:2.3:a:symantec:livestate_recovery:6.02:*:*:*:*:*:*:* | ||
cpe:2.3:a:symantec:norton_ghost:10.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:symantec:norton_ghost:10.0:*:dell:*:*:*:*:* | ||
cpe:2.3:a:symantec:norton_ghost:10.0:*:norton_system_works:*:*:*:*:* | ||
cpe:2.3:a:symantec:norton_ghost:10.01:*:*:*:*:*:*:* | ||
cpe:2.3:a:symantec:norton_save_and_recovery:1.01:*:sony_euro:*:*:*:*:* | ||
cpe:2.3:a:symantec:norton_save_and_recovery:1.01b:*:norton_system_works_2007:*:*:*:*:* | ||
cpe:2.3:a:symantec:norton_save_and_recovery:11.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:symantec:norton_save_and_recovery:11.01:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=520
- http://secunia.com/advisories/25013
- http://www.securitytracker.com/id?1017971=
- http://www.symantec.com/avcenter/security/Content/2007.04.26.html
- http://www.vupen.com/english/advisories/2007/1552
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33929
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=520
- http://secunia.com/advisories/25013
- http://www.securitytracker.com/id?1017971=
- http://www.symantec.com/avcenter/security/Content/2007.04.26.html
- http://www.vupen.com/english/advisories/2007/1552
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33929