Skip to content
COOEY

EXPOSURES › CVE-2022-20821

CVE-2022-20821

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-05-23 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-20821 ↗
⌖ EXPLOITED IN THE WILD SHAME 75/100 exploited-in-wilddefault-credsunpatched

Cisco IOS XR software health check opens TCP port 6379 by default, allowing attackers to access the Redis instance running within the NOSi container.

The default activation of a Redis service on an open port in Cisco IOS XR exposes a critical attack surface, enabling remote access to the NOSi container. DIB organizations must ensure default configurations are hardened and known open ports are strictly controlled to prevent unauthorized access and potential data breaches.

Shame score — Opening a sensitive service port by default on a network device is a negligent, avoidable misconfiguration that directly enables remote access to internal systems.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Cisco IOS XR software health check opens TCP port 6379 by default on activation. An attacker can connect to the Redis instance on the open port and allow access to the Redis instance that is running within the NOSi container.

AFFECTED FEDRAMP PRODUCTS · 9
PRODUCTSTATUS
AppDynamics GovAPM
AppDynamics (a Cisco company)
Authorized
Cisco Cloudlock for Government
Cisco Systems Inc.
Authorized
Cisco Meraki for Government
Cisco Systems Inc.
In Process
Cisco SD-WAN for Government
Cisco Systems Inc.
In Process
Cisco Umbrella for Government
Cisco Systems Inc.
In Process
Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)
Cisco Systems Inc.
Authorized
Duo Federal
Duo Security (A Cisco Company)
Authorized
WebEx Contact Center Enterprise for Government (WxCCE-G)
Cisco Systems Inc.
In Process
Webex for Government
Cisco Systems Inc.
Authorized