← Back to CVE List
Vulnerability Analysis
Cisco IOS XR Software Health Check Open Port Vulnerability

CVE-2022-20821

A vulnerability in the health check RPM of Cisco IOS XR Software could allow an unauthenticated, remote attacker to access the Redis instance that is running within the NOSi container. This vulnerability exists because the health check RPM opens TCP port 6379 by default upon activation. An attacker could exploit this vulnerability by connecting to the Redis instance on the open port. A successful exploit could allow the attacker to write to the Redis in-memory database, write arbitrary files to the container filesystem, and retrieve information about the Redis database. Given the configuration of the sandboxed container that the Redis instance runs in, a remote attacker would be unable to execute remote code or abuse the integrity of the Cisco IOS XR Software host system.

CISA KEV
CVSS Base Score
6.5
MEDIUM
Exploitability:3.9
Impact Score:2.6
Temporal Score:-
EPSS:11.76%

Threat Intelligence Signals

CISA KEV
YES
KEV Date Added
2022-05-23
Ransomware Use
Unknown
KEV Due Date
2022-06-13
VulnCheck In-the-Wild
No
Nuclei Template
No
EPSS Score
11.760%
EPSS Percentile
95.5th pct
GitHub Severity
MODERATE
SSVC Exploitation
SSVC Automatable
Vulnerability Class

Identity & Timeline

Status-
Assigning Authority-
CVSS Version / Source-
Reserved-
Published-
Patch Date (date_public)-
Exploit DB Date-
First GitHub PoC Date-
Last Updated-
Time to Patch (Days to fix)-
Exploit Release Gap-
PoC Release Gap-
Exploit DB ReferencesNone identified

Affected Products & Versions

Vendor Product Affected Versions
No affected products specified.

References

No reference links found.

LINK COPIED TO CLIPBOARD