ReQuest Serious Play F3 Media Server versions 7.0.3.4968 (Pro), 7.0.2.4954, 6.5.2.4954, 6.4.2.4681, 6.3.2.4203, and 2.0.1.823 allows unauthenticated attackers to disclose the webserver's Python debug log file containing system information, credentials, paths, processes and command arguments running on the device. Attackers can access sensitive information by visiting the message_log page.
History

Fri, 05 Dec 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 05 Dec 2025 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Request Serious Play
Request Serious Play request Serious Play
Request Serious Play request Serious Play Pro
Vendors & Products Request Serious Play
Request Serious Play request Serious Play
Request Serious Play request Serious Play Pro

Fri, 05 Dec 2025 17:30:00 +0000

Type Values Removed Values Added
Description ReQuest Serious Play F3 Media Server versions 7.0.3.4968 (Pro), 7.0.2.4954, 6.5.2.4954, 6.4.2.4681, 6.3.2.4203, and 2.0.1.823 allows unauthenticated attackers to disclose the webserver's Python debug log file containing system information, credentials, paths, processes and command arguments running on the device. Attackers can access sensitive information by visiting the message_log page.
Title ReQuest Serious Play F3 Media Server <= 7.0.3 Debug Log Disclosure2020
Weaknesses CWE-532
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-12-05T17:13:38.501Z

Updated: 2025-12-05T20:07:14.638Z

Reserved: 2025-12-05T12:03:28.231Z

Link: CVE-2020-36876

cve-icon Vulnrichment

Updated: 2025-12-05T20:07:09.750Z

cve-icon NVD

Status : Received

Published: 2025-12-05T18:15:53.207

Modified: 2025-12-05T18:15:53.207

Link: CVE-2020-36876

cve-icon Redhat

No data.