LIVE NEWSROOM · --:-- · May 24, 2026
A LIBRARY FOR SECURITY RESEARCHERS

CVE DATABASE  /  CVE-2022-20821

CVE-2022-20821

Cisco IOS XR Open Port Vulnerability

CVSS 6.5 · MEDIUM ⚠ CISA KEV — ACTIVELY EXPLOITED
On the CISA KEV catalog

Confirmed exploited in the wild. Added 2022-05-23. Federal remediation due 2022-06-13.
Required action: Apply updates per vendor instructions.

Summary

A vulnerability in the health check RPM of Cisco IOS XR Software could allow an unauthenticated, remote attacker to access the Redis instance that is running within the NOSi container. This vulnerability exists because the health check RPM opens TCP port 6379 by default upon activation. An attacker could exploit this vulnerability by connecting to the Redis instance on the open port. A successful exploit could allow the attacker to write to the Redis in-memory database, write arbitrary files to the container filesystem, and retrieve information about the Redis database. Given the configuration of the sandboxed container that the Redis instance runs in, a remote attacker would be unable to execute remote code or abuse the integrity of the Cisco IOS XR Software host system.

CVSS 3.1 breakdown

Base score6.5 (MEDIUM)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack vectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityLOW
IntegrityLOW
AvailabilityNONE

Weakness type (CWE)

Affected products

Cisco ios xrCisco 8201Cisco 8202Cisco 8208Cisco 8212Cisco 8218Cisco ncs-55a1-24hCisco ncs-55a1-24q6h-sCisco ncs-55a1-36h-sCisco ncs-55a1-36h-seCisco ncs-55a1-36h-se-sCisco ncs-55a2-mod-hd-sCisco ncs-55a2-mod-hx-sCisco ncs-55a2-mod-sCisco ncs-55a2-mod-se-h-sCisco ncs-55a2-mod-se-sCisco ncs 1001Cisco ncs 1002Cisco ncs 1004Cisco ncs 5001
Check this CVE live

Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.

References

Data: NIST NVD + CISA KEV. NVD last modified 2025-10-28. Always verify against the vendor advisory before acting.

Scroll to Top