← Vulnerability feed

Vulnerability record · CVE-2007-2360 · published 30 April 2007

CVE-2007-2360: Symantec backupexec system recovery vulnerability

Symantec · Backupexec System Recovery

Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, when remote backups of restore point images are configured, encrypt network share credentials with a key formed by a hash of the username, which allows local users to obtain the credentials by calculating the key.

6.8 CVSS 2.0 Medium EPSS 0.34% · top 75.6%
6.8CVSS 2.0 base score
0.34%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
10References
16 Jun 2026Last modified by NVD

Description

Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, when remote backups of restore point images are configured, encrypt network share credentials with a key formed by a hash of the username, which allows local users to obtain the credentials by calculating the key.

AV:L/AC:L/Au:S/C:C/I:C/A:C

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-2360 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-0457Symantec backupexec system recovery improper input validation vulnerabilityUnrestricted file upload vulnerability in the FileUpload class running on the Symantec LiveState Apache Tomcat server, as used by Symantec Backup Exe…EPSS 12%7.8CVE-2007-4347Symantec backupexec system recovery vulnerabilityMultiple integer overflows in the Job Engine (bengine.exe) service in Symantec Backup Exec for Windows Servers (BEWS) 11d build 11.0.7170 and 11.0.6.…EPSS 2.9%7.5CVE-2007-3666Symantec norton ghost vulnerabilityBuffer overflow in RemoteCommand.DLL in Symantec Norton Ghost 12.0 allows remote attackers to execute arbitrary code via the Connect function.EPSS 3.0%7.5CVE-2002-0345Symantec norton ghost vulnerabilitySymantec Ghost 7.0 stores usernames and passwords in plaintext in the NGServer\params registry key, which could allow an attacker to gain privileges.EPSS 1.6%7.2CVE-2007-2359Symantec backupexec system recovery vulnerabilityBuffer overflow in Ghost Service Manager, as used in Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recover…EPSS 0.41%5.5CVE-2011-3477Symantec backup exec system recovery improper input validation vulnerabilityGEAR Software CD DVD Filter driver (aka GEARAspiWDM.sys), as used in Symantec Backup Exec System Recovery 8.5 and BESR 2010, Symantec System Recovery…EPSS 0.62%5.0CVE-2008-2512Symantec backupexec system recovery path traversal vulnerabilityDirectory traversal vulnerability in Symantec Backup Exec System Recovery Manager 7.x before 7.0.4 and 8.x before 8.0.2 allows remote attackers to re…EPSS 2.8%5.0CVE-2007-4346Symantec backupexec system recovery vulnerabilityThe Job Engine (bengine.exe) service in Symantec Backup Exec for Windows Servers (BEWS) 11d build 11.0.7170 and 11.0.6.6235 allows remote attackers t…EPSS 2.6%

Source: NIST National Vulnerability Database (record CVE-2007-2360), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.