Tempest Security has reported a weakness in Polycom HDX 8000, which can be exploited by malicious users to disclose certain sensitive information.
Input passed via the "name" parameter to a_getlog.cgi is not properly verified before being used to download files. This can be exploited to download arbitrary files from local resources via directory traversal sequences.
The weakness is reported in versions 2.6 and prior.