Executive brief
A vulnerability in the health check RPM of Cisco IOS XR Software opens TCP port 6379 by default, allowing unauthenticated remote access to a Redis instance within a sandboxed container. Attackers can write to the Redis database and the container filesystem, though they cannot execute code on the host system.
Affected products
- Cisco IOS XR (none)
Timeline
- 2022-05-23: disclosed
- 2022-05-23: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-05-23: exploited: Reported as exploited in the wild.