CVE-2007-6638

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
04/01/2008
Last modified:
09/04/2025

Description

March Networks DVR 3204 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain usernames, passwords, device names, and IP addresses via a direct request for scripts/logfiles.tar.gz.

Vulnerable products and versions

CPE From Up to
cpe:2.3:h:march_networks:3204_dvr:*:*:*:*:*:*:*:*