CVE-2022-20821

Cisco IOS XR: Open Port

As of , CVE-2022-20821 in Cisco IOS XR is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch soon.

Exploited
Yes: CISA listed it on 23 May 2022
US federal deadline
13 June 202221 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
Not known to CISA
EPSS score
0.11Higher than 95% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
EPSS when listed
No score that dayThe EPSS file of the day CISA listed it has no score for it.
Public exploit
None foundNeither Metasploit nor Exploit-DB lists one.
Fix
No vendor link in CISA's entry

What CISA says to do

Apply updates per vendor instructions.

CISA's required action

What the flaw is

Cisco IOS XR software health check opens TCP port 6379 by default on activation. An attacker can connect to the Redis instance on the open port and allow access to the Redis instance that is running within the NOSi container.

CISA's description

A vulnerability in the health check RPM of Cisco IOS XR Software could allow an unauthenticated, remote attacker to access the Redis instance that is running within the NOSi container. This vulnerability exists because the health check RPM opens TCP port 6379 by default upon activation. An attacker could exploit this vulnerability by connecting to the Redis instance on the open port. A successful exploit could allow the attacker to write to the Redis in-memory database, write arbitrary files to the container filesystem, and retrieve information about the Redis database. Given the configuration of the sandboxed container that the Redis instance runs in, a remote attacker would be unable to execute remote code or abuse the integrity of the Cisco IOS XR Software host system.

The CVE record's description, from cisco

CVE published
26 May 2022
Assigned by
cisco
CVSS
6.5 Medium (CVSS 3.1, from the CNA)
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
CWE-923
Improper Restriction of Communication Channel to Intended Endpoints
CISA SSVC, exploitation
active
CISA SSVC, automatable
yes
CISA SSVC, technical impact
partial

Timeline

  1. CISA added it to its list of exploited vulnerabilities.
  2. The CVE record was published.
  3. The US federal deadline to fix it.

IOS XR: other exploited entries

VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2020-3118Software Discovery Protocol Format StringCisco IOS XRPatch soon0.12
CVE-2010-3035Border Gateway Protocol (BGP) Denial-of-ServiceCisco IOS XRPatch soon0.06
CVE-2020-3566Software DVMRP Memory ExhaustionCisco IOS XRPatch soon0.04
CVE-2009-2055Border Gateway Protocol (BGP) Denial-of-ServiceCisco IOS XRPatch soon0.03
CVE-2020-3569Software DVMRP Memory ExhaustionCisco IOS XRPatch soon0.03

Read further