CVE-2022-20821
unknown
KEV
CVSS v3
—
CVSS v2
—
VIR risk
1.5
Description
Cisco IOS XR software health check opens TCP port 6379 by default on activation. An attacker can connect to the Redis instance on the open port and allow access to the Redis instance that is running within the NOSi container.
CISA KEV
- Vendor
- Cisco
- Product
- IOS XR
- Due date
- 2022-06-13
Predictions
Exploit likelihood
99%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cisa-kev — https://nvd.nist.gov/vuln/detail/CVE-2022-20821
Exploits
References
Verify integrity in audit chain (admin only). AS-IS.