CVE-2022-20821
Cisco IOS XR Software Health Check Open Port Vulnerability
Vexday Risk Score
48Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 6.5EPSS 11.8%KEV simPoC —Nuclei —Metasploit —Patch referenciado
Lifecycle
23 May 2022Active exploitation (CISA KEV)
26 May 2022Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
In short
Cisco IOS XR Software exposes a Redis database on port 6379 without authentication, allowing remote attackers to read and write data to the database and container filesystem. While contained within a sandbox, this creates a risk of data manipulation and unauthorized access.
Technical detail
The health check RPM in Cisco IOS XR Software opens TCP port 6379 by default, exposing an unauthenticated Redis instance within the NOSi container. An unauthenticated remote attacker can connect to this port and perform read/write operations on the in-memory database and container filesystem; however, the sandboxed environment prevents host system compromise or remote code execution.
Summary generated and translated by AI from the official description.
A vulnerability in the health check RPM of Cisco IOS XR Software could allow an unauthenticated, remote attacker to access the Redis instance that is running within the NOSi container. This vulnerability exists because the health check RPM opens TCP port 6379 by default upon activation. An attacker could exploit this vulnerability by connecting to the Redis instance on the open port. A successful exploit could allow the attacker to write to the Redis in-memory database, write arbitrary files to the container filesystem, and retrieve information about the Redis database. Given the configuration of the sandboxed container that the Redis instance runs in, a remote attacker would be unable to execute remote code or abuse the integrity of the Cisco IOS XR Software host system.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Affected products
Cisco · Cisco IOS XR SoftwareWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →