peter bassill · operator
$ cve CVE-2022-20821 JSON

CVE-2022-20821 KEV

6.5
MEDIUM · CVSS 3.1 · EPSS 11.5% (pctl 96)

Patch first

On CISA KEV — known exploited in the wild, due 2022-06-13.

Description

A vulnerability in the health check RPM of Cisco IOS XR Software could allow an unauthenticated, remote attacker to access the Redis instance that is running within the NOSi container. This vulnerability exists because the health check RPM opens TCP port 6379 by default upon activation. An attacker could exploit this vulnerability by connecting to the Redis instance on the open port. A successful exploit could allow the attacker to write to the Redis in-memory database, write arbitrary files to the container filesystem, and retrieve information about the Redis database. Given the configuration of the sandboxed container that the Redis instance runs in, a remote attacker would be unable to execute remote code or abuse the integrity of the Cisco IOS XR Software host system.

Scoring

CVSS6.5 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS11.47% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-200
On CISA KEVyes — remediate by 2022-06-13
Public exploitnone known
Published2022-05-26
Last modified2026-06-17

CISA KEV

NameCisco IOS XR Open Port Vulnerability
Added2022-05-23
Due2022-06-13
Vendor / productCisco / IOS XR
Ransomware usenone reported

Affected (28)

VendorProduct
cisco8201
cisco8202
cisco8208
cisco8212
cisco8218
ciscoios xr
cisconcs 1001
cisconcs 1002
cisconcs 1004
cisconcs 5001
cisconcs 5002
cisconcs 5501-se
cisconcs 5502-se
cisconcs 5504
cisconcs 5508
cisconcs 5516
cisconcs 55a1
cisconcs 55a2
cisconcs-55a1-24h
cisconcs-55a1-24q6h-s
cisconcs-55a1-36h-s
cisconcs-55a1-36h-se
cisconcs-55a1-36h-se-s
cisconcs-55a2-mod-hd-s
cisconcs-55a2-mod-hx-s
cisconcs-55a2-mod-s
cisconcs-55a2-mod-se-h-s
cisconcs-55a2-mod-se-s

References

→ the Explorer  ·  watch your stack  ·  NVD