Junglewise Threat Intelligence

CVE-2022-20821: Cisco IOS XR Open Port Vulnerability

CVE-2022-20821 · Severity: critical · CVSS 6.5 · Exploited in the wild · Published 2022-05-23

Technologies: Cisco IOS XR. Vendors: Cisco.

Executive brief

A vulnerability in the health check RPM of Cisco IOS XR Software opens TCP port 6379 by default, allowing unauthenticated remote access to a Redis instance within a sandboxed container. Attackers can write to the Redis database and the container filesystem, though they cannot execute code on the host system.

Affected products

  • Cisco IOS XR (none)

Timeline

  • 2022-05-23: disclosed
  • 2022-05-23: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-05-23: exploited: Reported as exploited in the wild.

Related threats