← All CVEs

CVE-2022-20821

medium · 6.5Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-05-23Remediation due 2022-06-13

A vulnerability in the health check RPM of Cisco IOS XR Software could allow an unauthenticated, remote attacker to access the Redis instance that is running within the NOSi container. This vulnerability exists because the health check RPM opens TCP port 6379 by default upon activation. An attacker could exploit this vulnerability by connecting to the Redis instance on the open port. A successful exploit could allow the attacker to write to the Redis in-memory database, write arbitrary files to the container filesystem, and retrieve information about the Redis database. Given the configuration of the sandboxed container that the Redis instance runs in, a remote attacker would be unable to execute remote code or abuse the integrity of the Cisco IOS XR Software host system.

6.5
CVSS
12.1%
EPSS (exploit prob.)
96th
EPSS percentile
2022-05-26
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Weaknesses

CWE-200

Affected products

VendorProductAffected versions
ciscoios_xrall versions
cisco8201all versions
cisco8202all versions
cisco8208all versions
cisco8212all versions
cisco8218all versions
cisconcs-55a1-24hall versions
cisconcs-55a1-24q6h-sall versions
cisconcs-55a1-36h-sall versions
cisconcs-55a1-36h-seall versions
cisconcs-55a1-36h-se-sall versions
cisconcs-55a2-mod-hd-sall versions
cisconcs-55a2-mod-hx-sall versions
cisconcs-55a2-mod-sall versions
cisconcs-55a2-mod-se-h-sall versions
cisconcs-55a2-mod-se-sall versions
cisconcs_1001all versions
cisconcs_1002all versions
cisconcs_1004all versions
cisconcs_5001all versions
cisconcs_5002all versions
cisconcs_5501-seall versions
cisconcs_5502-seall versions
cisconcs_5504all versions
cisconcs_5508all versions
cisconcs_5516all versions
cisconcs_55a1all versions
cisconcs_55a2all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2022-20821