{"schema_version":"public-product-v1.1","generated_at":"2026-07-21T10:40:20Z","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","advisory":{"id":"Cisco-SA-20141217-CVE-2014-8006","slug":"cisco-sa-20141217-cve-2014-8006","vendor":"Cisco","title":"Cisco ISB8320-E High-Definition IP-Only DVR Remote Unauthenticated Access Vulnerability","summary":"An issue in Disaster Recovery (DRA) mode of the Cisco ISB8320-E High-Definition IP-Only DVR could allow an unauthenticated, remote attacker to access the device via telnet without authentication for the duration of the recovery boot. The issue is due to the disaster recovery process. An attacker could exploit this vulnerability by attempting to access the device via telnet during the disaster recovery mode period of execution. An exploit could allow the attacker to obtain access to the device via unauthenticated telnet. Functional code that exploits this vulnerability is publicly available. Cisco has confirmed the vulnerability but updated software is not available. To exploit the vulnerability, the attacker may need to have access to trusted or internal networks to be able to connect to the targeted system. This access requirement could limit the likelihood of a successful exploit.","severity":"Medium","published_at":"2014-12-17T18:02:02Z","updated_at":"2014-12-17T18:02:02Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-SA-20141217-CVE-2014-8006","csaf_url":"https://sec.cloudapps.cisco.com/security/center/contentjson/CiscoSecurityAdvisory/Cisco-SA-20141217-CVE-2014-8006/csaf/Cisco-SA-20141217-CVE-2014-8006.json","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure."},"freshness":{"last_source_refreshed_at":"2026-07-21T05:16:34Z","latest_source_refresh_at":"2026-07-21T05:16:34Z","oldest_source_refresh_at":"2026-07-21T03:00:03Z","all_sources_fresh":true,"sources":[{"source":"cisco_advisories","label":"Cisco advisories","last_success_at":"2026-07-21T03:00:03Z","stale":false},{"source":"cisco_csaf","label":"Cisco CSAF","last_success_at":"2026-07-21T05:14:24Z","stale":false},{"source":"nvd_cves","label":"NVD CVEs","last_success_at":"2026-07-21T05:16:30Z","stale":false},{"source":"cisa_kev","label":"CISA KEV","last_success_at":"2026-07-21T05:16:31Z","stale":false},{"source":"first_epss","label":"EPSS","last_success_at":"2026-07-21T05:16:34Z","stale":false}]},"summary":{"cve_count":1,"visible_product_count":1,"public_evidence_count":1,"kev_count":0,"highest_epss":0.01187},"cves":[{"id":"CVE-2014-8006","kev":false,"epss":{"score":0.01187,"percentile":0.6444,"score_date":"2026-07-20","updated_at":"2026-07-21T05:16:32Z"}}],"public_evidence":[{"product":{"name":"Cisco ISB8320-E IP Only DVR","slug":"cisco-isb8320-e-ip-only-dvr","vendor":"Cisco"},"cve":{"id":"CVE-2014-8006"},"evidence_type":"structured_affected","evidence_label":{"scope":"CSAF product evidence","label":"product_status known affected"},"evidence_source":"Cisco CSAF","source":"Cisco CSAF","source_document_fetched_at":"2026-07-20T04:05:18Z","csaf_status":"known_affected","csaf_product_status":"known_affected","csaf_product_status_path":"vulnerabilities[].product_status.known_affected","raw_product_name":"Cisco ISB8320-E IP Only DVR","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","exposure_verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","kev":false,"epss":{"score":0.01187,"score_date":"2026-07-20","updated_at":"2026-07-21T05:16:32Z"},"published_at":"2014-12-17T18:02:02Z","updated_at":"2014-12-17T18:02:02Z","advisory_updated_at":"2014-12-17T18:02:02Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-SA-20141217-CVE-2014-8006","row_display_order":1}]}