LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-20821: Cisco IOS XR Open Port Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 23, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 13, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-20821 to its Known Exploited Vulnerabilities catalog on May 23, 2022, with a federal patch deadline of Jun 13, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Cisco IOS XR software health check opens TCP port 6379 by default on activation. An attacker can connect to the Redis instance on the open port and allow access to the Redis instance that is running…

CVE-2022-20821 is an open-port vulnerability in Cisco IOS XR software. When a health-check feature is activated, the software opens TCP port 6379 by default, exposing a Redis instance that runs inside the NOSi container. An unauthenticated attacker who can reach that port may connect to the Redis service. Because IOS XR is commonly used on service-provider and enterprise routing platforms, an exposed management or control-plane interface can give an attacker a foothold on critical network infrastructure. Confirm exact impact and fixed releases against the vendor advisory.

How it works

The weakness is classified as CWE-923 (improper restriction of communication channel to intended endpoints). In this case the health-check function starts a Redis instance inside the NOSi container and binds it to TCP 6379 without adequate access controls. Once the port is listening, any host that can reach the device on that port can open a connection to the Redis service. The CISA summary states that an attacker can thereby gain access to the Redis instance running within the container. No further exploit mechanics are provided in the public record; defenders should treat any reachable Redis endpoint on an IOS XR device as a potential unauthorized-access vector and verify details in Cisco’s advisory.

Am I affected? How to find it in your systems

Cisco IOS XR typically runs on carrier-grade and large-enterprise routers and related network elements. Inventory every device that reports an IOS XR image:

Compare discovered versions and feature states against the fixed releases listed by Cisco; do not rely on version ranges stated elsewhere.

How to remediate

The required action is to apply the updates published by Cisco. Obtain the fixed software image from the vendor, validate its integrity, and schedule installation according to your change process. After the upgrade:

Document the change and re-scan to verify the port is closed or properly filtered.

If you can't patch immediately

Until the vendor update can be installed, reduce exposure with compensating controls:

These steps do not replace the patch; they only lower risk until the official update is applied.

If your data may have been exposed

Actively exploited vulnerabilities can lead to unauthorized access and subsequent data exposure. While ransomware use of this CVE is not documented, any successful connection to the Redis instance should be treated as a potential compromise. Review device configurations, logs, and downstream systems for signs of lateral movement or data exfiltration. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether associated credentials have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · IOS XR
WeaknessCWE-923
Added to CISA KEVMay 23, 2022
Federal patch deadlineJun 13, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities