MEDIUM · 6.8

CVE-2007-2360

Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, when remote backups of restore point images are configured, encrypt network share cre...

Vulnerability Description

Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, when remote backups of restore point images are configured, encrypt network share credentials with a key formed by a hash of the username, which allows local users to obtain the credentials by calculating the key.

CVSS Score

6.8

MEDIUM

AV:L/AC:L/Au:S/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
SymantecBackupexec System Recovery6.5
SymantecLivestate Recovery6.0
SymantecNorton Ghost10.0
SymantecNorton Save And Recovery1.01

References

FAQ

What is CVE-2007-2360?

CVE-2007-2360 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, when remote backups of restore point images are configured, encrypt network share cre...

How severe is CVE-2007-2360?

CVE-2007-2360 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-2360?

Check the references section above for vendor advisories and patch information. Affected products include: Symantec Backupexec System Recovery, Symantec Livestate Recovery, Symantec Norton Ghost, Symantec Norton Save And Recovery.