CVE-2022-20821 is a critical vulnerability in the health check RPM of Cisco IOS XR Software, allowing unauthenticated, remote attackers to access the Redis instance running within the NOSi container. This vulnerability, stemming from TCP port 6379 being open by default, enables attackers to write to the Redis in-memory database, write arbitrary files to the container filesystem, and retrieve database information. While it does not permit remote code execution on the host system, its CVSS score of 6.5 (Medium) is misleading given its active exploitation in the wild, as confirmed by CISA and a FAUCET Risk Score of 99/100. Despite no public Metasploit or ExploitDB modules, the vulnerability has garnered significant community discussion and media coverage, indicating widespread awareness and concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xr:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.