Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and...
Vulnerability Description
Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, when remote backups of restore points images are configured, uses weak permissions (world readable) for a configuration file with network share credentials, which allows local users to obtain the credentials by reading the file.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-2361
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securitytracker.com/id?1017971
- http://www.vupen.com/english/advisories/2007/1552
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=520
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33929
- http://www.symantec.com/avcenter/security/Content/2007.04.26.html
- http://secunia.com/advisories/25013
More from symantec
View All →Affected Vendor
symantec
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.