← Vulnerability feed

Vulnerability record · CVE-2022-20821 · published 26 May 2022

CVE-2022-20821: Cisco IOS XR health check RPM exposes Redis port without authentication

Cisco · Ios Xr

The health check RPM in Cisco IOS XR Software opens TCP port 6379 by default when activated, exposing the Redis instance inside the NOSi container. An unauthenticated remote attacker can connect to that Redis instance and write to its in-memory database, write arbitrary files to the container filesystem, and read database information. The flaw matters because a management-plane service is reachable without credentials, though Cisco states the container sandbox prevents code execution or compromise of the IOS XR host.

6.5 CVSS 3.1 Medium CISA KEV since 23 May 2022 EPSS 11% · top 4.1% CWE-200 · Information exposure
6.5CVSS 3.1 base score, v2 6.4
11%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the health check RPM of Cisco IOS XR Software could allow an unauthenticated, remote attacker to access the Redis instance that is running within the NOSi container. This vulnerability exists because the health check RPM opens TCP port 6379 by default upon activation. An attacker could exploit this vulnerability by connecting to the Redis instance on the open port. A successful exploit could allow the attacker to write to the Redis in-memory database, write arbitrary files to the container filesystem, and retrieve information about the Redis database. Given the configuration of the sandboxed container that the Redis instance runs in, a remote attacker would be unable to execute remote code or abuse the integrity of the Cisco IOS XR Software host system.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw is unauthenticated and remotely reachable and is listed in CISA KEV as exploited, though CVSS rates impact medium and Cisco states host code execution is not possible.

What it is

The health check RPM in Cisco IOS XR Software opens TCP port 6379 by default when activated, exposing the Redis instance inside the NOSi container. An unauthenticated remote attacker can connect to that Redis instance and write to its in-memory database, write arbitrary files to the container filesystem, and read database information. The flaw matters because a management-plane service is reachable without credentials, though Cisco states the container sandbox prevents code execution or compromise of the IOS XR host.

Impact

An attacker gains unauthenticated read and write access to the container's Redis data and can drop arbitrary files into the container filesystem. Cisco states remote code execution and host integrity abuse are not possible given the container configuration.

Attack surface

Reachable over the network on TCP port 6379, which the health check RPM opens by default upon activation. No authentication and no user interaction are required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

CVE-2022-20821 is listed in CISA KEV with a required action deadline of 2022-06-13, indicating known exploitation. EPSS shows a 30-day probability of roughly 12.1 percent (95.9th percentile); references are vendor advisory and US government resources only, with no public exploit tag.

What to do

  • Apply the Cisco IOS XR software updates referenced in the vendor advisory cisco-sa-iosxr-redis-ABJyE5xK.
  • If the health check RPM is not required, deactivate it to stop port 6379 from being opened.
  • Block or restrict inbound TCP 6379 to IOS XR management interfaces using ACLs or infrastructure firewalls.
  • Audit IOS XR devices for unexpected listeners on 6379 and remove any unneeded exposure.
  • Track the CISA KEV remediation deadline and confirm patched devices before it lapses.

Detection

  • Monitor for inbound connections to TCP port 6379 on IOS XR devices and management networks.
  • Alert on Redis protocol commands or unusual traffic patterns directed at IOS XR nodes.
  • Review container filesystem changes or unexpected files written by the Redis process.
  • Check IOS XR configuration and process state for the health check RPM and its listening ports.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2022-20821 to the Known Exploited Vulnerabilities catalog on 23 May 2022 as "Cisco IOS XR Open Port Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 13 June 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-20821 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-3118Cisco IOS XR CDP packet parsing flaw allows adjacent code executionCisco IOS XR's Cisco Discovery Protocol implementation fails to properly validate string input in certain CDP message fields, allowing a stack overfl…KEVEPSS 12%analysed8.8CVE-2018-0167Cisco IOS, IOS XE and IOS XR LLDP buffer overflowMultiple buffer overflow flaws exist in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE and IOS XR Software. An unauthenticat…KEVEPSS 3.4%analysed8.6CVE-2020-3569Cisco IOS XR DVMRP IGMP packet handling memory exhaustionCisco IOS XR Software mishandles IGMP packets in its Distance Vector Multicast Routing Protocol (DVMRP) feature, allowing crafted traffic to crash th…KEVEPSS 3.3%analysed8.6CVE-2020-3566Cisco IOS XR DVMRP IGMP queue flaw causes memory exhaustionCisco IOS XR Software mishandles queue management for IGMP packets in its DVMRP feature, allowing uncontrolled memory consumption. An unauthenticated…KEVEPSS 3.7%analysed8.0CVE-2018-0175Cisco IOS, IOS XE and IOS XR LLDP format string flawA format string vulnerability exists in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE and IOS XR Software. An unauthenticat…KEVEPSS 3.5%analysed7.5CVE-2016-6415Cisco IOS IKEv1 memory disclosure via SA negotiationThe IKEv1 server implementation in Cisco IOS, IOS XE, IOS XR and PIX mishandles Security Association negotiation requests, allowing a remote attacker…KEVEPSS 88%analysed7.5CVE-2010-3035Cisco IOS XR BGP peering reset via unrecognized transitive attributeCisco IOS XR 3.4.0 through 3.9.1 mishandles unrecognized transitive BGP attributes when BGP is enabled, allowing a crafted prefix announcement to res…KEVEPSS 5.7%analysed5.9CVE-2009-2055Cisco IOS XR BGP invalid attribute causes session reset DoSCisco IOS XR 3.4.0 through 3.8.1 fails to properly validate a BGP UPDATE message attribute, allowing a remote peer to reset BGP sessions. Because BGP…KEVEPSS 3.3%analysed

Source: NIST National Vulnerability Database (record CVE-2022-20821), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.