OSVDB ID: 39726

Title: March Networks 3204 DVR Logfile Information Disclosure

Info

Disclosure

Dec 28, 2007

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

March Networks 3204 DVR contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when specific logfiles are downloaded, which contain sensitive information by accessing a specific URL resulting in a loss of confidentiality.

Classification

Location: Local Access Required
Attack Type: Information Disclosure
Impact: Loss of Confidentiality, Loss of Integrity
Solution: Patch / RCS
Exploit: Exploit Public
Disclosure: Vendor Verified

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, March Networks has released a patch to address this vulnerability.

Products

March Networks

3204 DVR

N/A

References

Credit

  • Alex Hernandez - ahernandezsybsecurity.com - SYB Security


Direct URL: http://osvdb.org/39726