vendor:
DVR 3204
by:
Alex Hernandez
5.5
CVSS
MEDIUM
Information Disclosure
200
CWE
Product Name: DVR 3204
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
March Networks DVR 3204 Logfile Information Disclosure Exploit
The exploit allows any user to obtain log files without authentication by accessing a specific path on the DVR. This can lead to the disclosure of sensitive information such as usernames, passwords, device names, and IP addresses.
Mitigation:
Apply a patch or update to the latest firmware version that addresses the vulnerability. Restrict access to the log files and ensure proper authentication is required.