CVE-2007-2360Backupexec System Recovery vulnerability

3 documents3 sources
Severity
6.8MEDIUMNVD
EPSS
0.1%
top 81.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 30
Latest updateMay 1

Description

Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, when remote backups of restore point images are configured, encrypt network share credentials with a key formed by a hash of the username, which allows local users to obtain the credentials by calculating the key.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.1 | Impact: 10.0

Affected Packages4 packages

NVDsymantec/livestate_recovery6.0, 6.01, 6.02+2
NVDsymantec/norton_ghost10.0, 10.01+1

🔴Vulnerability Details

2
GHSA
GHSA-jxcw-5f6w-xx32: Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, when remote backups of restore poin2022-05-01
CVEList
CVE-2007-2360: Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, when remote backups of restore poin2007-04-30
CVE-2007-2360 — Symantec vulnerability | cvebase