Cisco ISB8320-E High-Definition IP-Only DVR Remote Unauthenticated Access Vulnerability

Related Vulnerabilities: CVE-2014-8006  

An issue in Disaster Recovery (DRA) mode of the Cisco ISB8320-E High-Definition IP-Only DVR could allow an unauthenticated, remote attacker to access the device via telnet without authentication for the duration of the recovery boot. The issue is due to the disaster recovery process. An attacker could exploit this vulnerability by attempting to access the device via telnet during the disaster recovery mode period of execution. An exploit could allow the attacker to obtain access to the device via unauthenticated telnet. Functional code that exploits this vulnerability is publicly available. Cisco has confirmed the vulnerability but updated software is not available. To exploit the vulnerability, the attacker may need to have access to trusted or internal networks to be able to connect to the targeted system. This access requirement could limit the likelihood of a successful exploit.