Vulnerability record · CVE-2022-20821 · published 26 May 2022
CVE-2022-20821: Cisco IOS XR health check RPM exposes Redis port without authentication
Cisco · Ios Xr
The health check RPM in Cisco IOS XR Software opens TCP port 6379 by default when activated, exposing the Redis instance inside the NOSi container. An unauthenticated remote attacker can connect to that Redis instance and write to its in-memory database, write arbitrary files to the container filesystem, and read database information. The flaw matters because a management-plane service is reachable without credentials, though Cisco states the container sandbox prevents code execution or compromise of the IOS XR host.
Description
A vulnerability in the health check RPM of Cisco IOS XR Software could allow an unauthenticated, remote attacker to access the Redis instance that is running within the NOSi container. This vulnerability exists because the health check RPM opens TCP port 6379 by default upon activation. An attacker could exploit this vulnerability by connecting to the Redis instance on the open port. A successful exploit could allow the attacker to write to the Redis in-memory database, write arbitrary files to the container filesystem, and retrieve information about the Redis database. Given the configuration of the sandboxed container that the Redis instance runs in, a remote attacker would be unable to execute remote code or abuse the integrity of the Cisco IOS XR Software host system.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Automated analysis
high priorityThe flaw is unauthenticated and remotely reachable and is listed in CISA KEV as exploited, though CVSS rates impact medium and Cisco states host code execution is not possible.
What it is
The health check RPM in Cisco IOS XR Software opens TCP port 6379 by default when activated, exposing the Redis instance inside the NOSi container. An unauthenticated remote attacker can connect to that Redis instance and write to its in-memory database, write arbitrary files to the container filesystem, and read database information. The flaw matters because a management-plane service is reachable without credentials, though Cisco states the container sandbox prevents code execution or compromise of the IOS XR host.
Impact
An attacker gains unauthenticated read and write access to the container's Redis data and can drop arbitrary files into the container filesystem. Cisco states remote code execution and host integrity abuse are not possible given the container configuration.
Attack surface
Reachable over the network on TCP port 6379, which the health check RPM opens by default upon activation. No authentication and no user interaction are required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
CVE-2022-20821 is listed in CISA KEV with a required action deadline of 2022-06-13, indicating known exploitation. EPSS shows a 30-day probability of roughly 12.1 percent (95.9th percentile); references are vendor advisory and US government resources only, with no public exploit tag.
What to do
- Apply the Cisco IOS XR software updates referenced in the vendor advisory cisco-sa-iosxr-redis-ABJyE5xK.
- If the health check RPM is not required, deactivate it to stop port 6379 from being opened.
- Block or restrict inbound TCP 6379 to IOS XR management interfaces using ACLs or infrastructure firewalls.
- Audit IOS XR devices for unexpected listeners on 6379 and remove any unneeded exposure.
- Track the CISA KEV remediation deadline and confirm patched devices before it lapses.
Detection
- Monitor for inbound connections to TCP port 6379 on IOS XR devices and management networks.
- Alert on Redis protocol commands or unusual traffic patterns directed at IOS XR nodes.
- Review container filesystem changes or unexpected files written by the Redis process.
- Check IOS XR configuration and process state for the health check RPM and its listening ports.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-20821 to the Known Exploited Vulnerabilities catalog on 23 May 2022 as "Cisco IOS XR Open Port Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 13 June 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-20821 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-20821), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.