---------------------------------------------------------------------- A new version (0.9.0.0 - Release Candidate 1) of the free Secunia PSI has been released. The new version includes many new and advanced features, which makes it even easier to stay patched. Download and test it today: https://psi.secunia.com/ Read more about this new version: https://psi.secunia.com/?page=changelog ---------------------------------------------------------------------- TITLE: March Networks 3204 DVR Logfile Information Disclosure SECUNIA ADVISORY ID: SA28211 VERIFY ADVISORY: http://secunia.com/advisories/28211/ CRITICAL: Less critical IMPACT: Exposure of sensitive information WHERE: >From local network OPERATING SYSTEM: March Networks 3204 DVR http://secunia.com/product/17052/ DESCRIPTION: Alex Hernandez has reported a security issue in March Networks 3204 DVR, which can be exploited by malicious people to disclose sensitive information. The problem is that it is possible to download the logfiles, which contain certain sensitive information (e.g. usernames and passwords), by accessing a specific URL. The security issue is reported in 3204 DVR. Other versions may also be affected. SOLUTION: The vendor has reportedly released a fix. PROVIDED AND/OR DISCOVERED BY: Alex Hernandez, SYB Security ORIGINAL ADVISORY: http://www.sybsecurity.com/advisors/SYBSEC-ADV14-March_Networks_DVR_3204_Logfile_Information_Disclosure ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------