4.9

CVE-2007-2361

Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, when remote backups of restore points images are configured, uses weak permissions (world readable) for a configuration file with network share credentials, which allows local users to obtain the credentials by reading the file.

Data is provided by the National Vulnerability Database (NVD)
SymantecLivestate Recovery Version6.0
SymantecLivestate Recovery Version6.01
SymantecLivestate Recovery Version6.02
SymantecNorton Ghost Version10.0
SymantecNorton Ghost Version10.0 Editiondell
SymantecNorton Ghost Version10.0 Editionnorton_system_works
SymantecNorton Ghost Version10.01
SymantecNorton Save And Recovery Version1.01 Editionsony_euro
SymantecNorton Save And Recovery Version1.01b Editionnorton_system_works_2007
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.07% 0.22
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.9 3.9 6.9
AV:L/AC:L/Au:N/C:C/I:N/A:N