Vulnerability Details CVE-2007-2361
Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, when remote backups of restore points images are configured, uses weak permissions (world readable) for a configuration file with network share credentials, which allows local users to obtain the credentials by reading the file.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 22.2%
CVSS Severity
CVSS v2 Score 4.9
Products affected by CVE-2007-2361
-
cpe:2.3:a:symantec:backupexec_system_recovery:6.5
-
cpe:2.3:a:symantec:backupexec_system_recovery:6.52
-
cpe:2.3:a:symantec:backupexec_system_recovery:6.52a
-
cpe:2.3:a:symantec:backupexec_system_recovery:6.53
-
cpe:2.3:a:symantec:livestate_recovery:6.0
-
cpe:2.3:a:symantec:livestate_recovery:6.01
-
cpe:2.3:a:symantec:livestate_recovery:6.02
-
cpe:2.3:a:symantec:norton_ghost:10.0
-
cpe:2.3:a:symantec:norton_ghost:10.01
-
cpe:2.3:a:symantec:norton_save_and_recovery:1.01
-
cpe:2.3:a:symantec:norton_save_and_recovery:1.01b
-
cpe:2.3:a:symantec:norton_save_and_recovery:11.0
-
cpe:2.3:a:symantec:norton_save_and_recovery:11.01
-
cpe:2.3:a:symantec:norton_save_and_recovery:11.01b