CVE-2007-6638
Estado: ModificadaAlta (10)—
March Networks DVR 3204 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain usernames, passwords, device names, and IP addresses via a direct request for scripts/logfiles.tar.gz.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
- Puntuación base: 10
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 13%
- Percentil entre todas las CVEs puntuadas: 96
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-264
Referencias
- http://osvdb.org/39726
- http://secunia.com/advisories/28211
- http://www.milw0rm.com/papers/190
- http://www.securityfocus.com/bid/27054
- http://www.sybsecurity.com/advisors/SYBSEC-ADV14-March_Networks_DVR_3204_Logfile_Information_Disclosure
- http://www.sybsecurity.com/pages/advisors/static/dvr3204_exp.txt
- http://www.sybsecurity.com/resources/static/An_Insecurity_Overview_of_the_March_Networks_DVR-CCTV_3204.pdf
- https://www.exploit-db.com/exploits/4797
- http://osvdb.org/39726
- http://secunia.com/advisories/28211
- http://www.milw0rm.com/papers/190
- http://www.securityfocus.com/bid/27054
- http://www.sybsecurity.com/advisors/SYBSEC-ADV14-March_Networks_DVR_3204_Logfile_Information_Disclosure
- http://www.sybsecurity.com/pages/advisors/static/dvr3204_exp.txt
- http://www.sybsecurity.com/resources/static/An_Insecurity_Overview_of_the_March_Networks_DVR-CCTV_3204.pdf
- https://www.exploit-db.com/exploits/4797
JSON original (NVD)
Mostrar
{
"id": "CVE-2007-6638",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2008-01-04T00:46:00.000",
"references": [
{
"url": "http://osvdb.org/39726",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/28211",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.milw0rm.com/papers/190",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/27054",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.sybsecurity.com/advisors/SYBSEC-ADV14-March_Networks_DVR_3204_Logfile_Information_Disclosure",
"source": "cve@mitre.org"
},
{
"url": "http://www.sybsecurity.com/pages/advisors/static/dvr3204_exp.txt",
"source": "cve@mitre.org"
},
{
"url": "http://www.sybsecurity.com/resources/static/An_Insecurity_Overview_of_the_March_Networks_DVR-CCTV_3204.pdf",
"source": "cve@mitre.org"
},
{
"url": "https://www.exploit-db.com/exploits/4797",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/39726",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/28211",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.milw0rm.com/papers/190",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/27054",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.sybsecurity.com/advisors/SYBSEC-ADV14-March_Networks_DVR_3204_Logfile_Information_Disclosure",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.sybsecurity.com/pages/advisors/static/dvr3204_exp.txt",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.sybsecurity.com/resources/static/An_Insecurity_Overview_of_the_March_Networks_DVR-CCTV_3204.pdf",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.exploit-db.com/exploits/4797",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "March Networks DVR 3204 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain usernames, passwords, device names, and IP addresses via a direct request for scripts/logfiles.tar.gz."
},
{
"lang": "es",
"value": "March Networks DVR 3204 almacena información sensible bajo la raíz web con control de acceso insuficiente, lo cual permite a atacantes remotos obtener nombres de usuario, contraseñas, nombres de dispositivo, y direcciones IP mediante una petición directa de scripts/logfiles.tar.gz."
}
],
"lastModified": "2026-06-16T22:48:29.260",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:march_networks:3204_dvr:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1A8F803C-CD2B-4E0E-A70C-A721D63D1C7C"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}