« Volver al listado

CVE-2007-2360

Estado: ModificadaMedia (6.8)—

Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, when remote backups of restore point images are configured, encrypt network share credentials with a key formed by a hash of the username, which allows local users to obtain the credentials by calculating the key.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2007-2360",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:S/C:C/I:C/A:C",
          "authentication": "SINGLE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": true,
        "exploitabilityScore": 3.1,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-04-30T22:19:00.000",
  "references": [
    {
      "url": "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=520",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/25013",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securitytracker.com/id?1017971",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.symantec.com/avcenter/security/Content/2007.04.26.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/1552",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=520",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/25013",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id?1017971",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.symantec.com/avcenter/security/Content/2007.04.26.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/1552",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, when remote backups of restore point images are configured, encrypt network share credentials with a key formed by a hash of the username, which allows local users to obtain the credentials by calculating the key."
    },
    {
      "lang": "es",
      "value": "Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, y BackupExec System Recovery anterior a 20070426, cuando están los backups remotos de las imágenes del punto de restauración configurados, cifra las credenciales de la parte de la red con una llave formada por un hash del username, que permite que los usuarios locales obtengan las credenciales calculando la llave."
    }
  ],
  "lastModified": "2026-06-16T22:39:26.097",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:symantec:backupexec_system_recovery:6.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D0598D0E-0BCA-4711-89DE-53C528D9015B"
            },
            {
              "criteria": "cpe:2.3:a:symantec:backupexec_system_recovery:6.52:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8BAB9A49-0311-4D33-8F58-F1228CABA8EC"
            },
            {
              "criteria": "cpe:2.3:a:symantec:backupexec_system_recovery:6.52a:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2942EF66-62D1-49F9-A38C-BFEEAD22F62E"
            },
            {
              "criteria": "cpe:2.3:a:symantec:backupexec_system_recovery:6.53:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CC7F5F20-B428-4754-9274-F16BC01E8957"
            },
            {
              "criteria": "cpe:2.3:a:symantec:livestate_recovery:6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "33F3C4CA-B6D1-4B7A-9C98-8CE0A71C86DF"
            },
            {
              "criteria": "cpe:2.3:a:symantec:livestate_recovery:6.01:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5E137FF2-AEC3-48CD-B744-76615B433554"
            },
            {
              "criteria": "cpe:2.3:a:symantec:livestate_recovery:6.02:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "880D2EE8-DB5C-478A-86F6-1960C1F68E52"
            },
            {
              "criteria": "cpe:2.3:a:symantec:norton_ghost:10.0:*:dell:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "48289358-FC5D-4CC9-B420-365B1FB842F5"
            },
            {
              "criteria": "cpe:2.3:a:symantec:norton_ghost:10.0:*:norton_system_works:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6A43FA5B-E637-41B3-BCD9-A3DF2A372DE9"
            },
            {
              "criteria": "cpe:2.3:a:symantec:norton_ghost:10.01:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3F6128F8-5BE1-4A5A-BCEF-D0C9F94E306E"
            },
            {
              "criteria": "cpe:2.3:a:symantec:norton_save_and_recovery:1.01:*:sony_euro:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A059387D-6A4E-4F23-B16F-9C04601A556D"
            },
            {
              "criteria": "cpe:2.3:a:symantec:norton_save_and_recovery:1.01b:*:norton_system_works_2007:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D4EE821D-CCA3-43C7-8044-31F9373AA8FB"
            },
            {
              "criteria": "cpe:2.3:a:symantec:norton_save_and_recovery:11.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8881CCEE-CDC3-4634-AD25-C705FD8BDE9D"
            },
            {
              "criteria": "cpe:2.3:a:symantec:norton_save_and_recovery:11.01:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DD4775B1-3712-429D-9227-824CFAB69FE0"
            },
            {
              "criteria": "cpe:2.3:a:symantec:norton_save_and_recovery:11.01b:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "082E74B5-1045-4BCF-93A2-AF0AFF4EAA00"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "evaluatorImpact": "\"In order for this exploit to have an impact, administrators would either have to configure client machines to save restore points images to a private share, or the vulnerable machine would have to be shared by several users who each saved their restore points images to private shares.\"",
  "sourceIdentifier": "cve@mitre.org"
}