A vulnerability in the health check RPM of Cisco IOS XR Software could allow an unauthenticated, remote attacker to access the Redis instance that is running within the NOSi container. This vulnerability exists because the health check RPM opens TCP port 6379 by default upon activation. An attacker could exploit this vulnerability by connecting to the Redis instance on the open port. A successful exploit could allow the attacker to write to the Redis in-memory database, write arbitrary files to the container filesystem, and retrieve information about the Redis database. Given the configuration of the sandboxed container that the Redis instance runs in, a remote attacker would be unable to execute remote code or abuse the integrity of the Cisco IOS XR Software host system.
Connections 29
has cited scope1 retained · stored CVE-2022-20821 → Cisco · Cisco IOS XR Softwareae23ae2c-1337-4742-91ca-61abf8523587
has environmental constraint1 retained · stored CVE-2022-20821 → cisco · ncs_550803a05ef6-8889-4c43-8d53-687f8b246086
has environmental constraint1 retained · stored CVE-2022-20821 → cisco · ncs-55a2-mod-hd-scb656dc0-def4-418a-bab1-8374f559a53e
has environmental constraint1 retained · stored CVE-2022-20821 → cisco · 82010237c84b-8785-48a4-b9fb-04ccb943caf9
has environmental constraint1 retained · stored CVE-2022-20821 → cisco · ncs_550480785d56-01f6-44c8-b8bb-ddf07b1c0420
has environmental constraint1 retained · stored CVE-2022-20821 → cisco · ncs_5516cf5c89b4-369d-494a-8671-99061662cf5d
has environmental constraint1 retained · stored CVE-2022-20821 → cisco · ncs-55a1-36h-se-sed7440f9-73b2-4492-a623-cb096bbe5ee3
has environmental constraint1 retained · stored CVE-2022-20821 → cisco · ncs-55a1-24h0bb91d79-de5f-4472-afdb-5316d8ef9b0f
has environmental constraint1 retained · stored CVE-2022-20821 → cisco · ncs-55a1-36h-sef0ed32a0-3230-4a78-ac9f-7675595f34ff
has environmental constraint1 retained · stored CVE-2022-20821 → cisco · ncs_100102da7e52-47dc-430f-88c2-f100932d59ec
has environmental constraint1 retained · stored CVE-2022-20821 → cisco · ncs_10020cd67a87-1f84-4a49-8a70-f2babb994b37
has environmental constraint1 retained · stored CVE-2022-20821 → cisco · 821868707bdd-cf1a-40a8-9092-14eec43482cb
has environmental constraint1 retained · stored CVE-2022-20821 → cisco · ncs_5002547d2796-2fce-4d15-baff-a6e285041642
has environmental constraint1 retained · stored CVE-2022-20821 → cisco · 8208991197a5-5f77-45a3-8859-9e2a8e8b2c1c
has environmental constraint1 retained · stored CVE-2022-20821 → cisco · ncs-55a2-mod-se-h-s0ab6f9cb-98c0-4e38-ad96-4ab5cc17fdf8
has environmental constraint1 retained · stored CVE-2022-20821 → cisco · ncs-55a2-mod-se-s9bbba4b3-d94d-4f5a-ae3c-8371b16f3312
has environmental constraint1 retained · stored CVE-2022-20821 → cisco · ncs_5001b4882b4d-8889-4cc4-b7fc-20183a806c92
has environmental constraint1 retained · stored CVE-2022-20821 → cisco · ncs_55a1f2eb4b62-78bf-4e76-b2c7-c6aa5034fbb9
has environmental constraint1 retained · stored CVE-2022-20821 → cisco · ncs-55a1-36h-sce5c449a-b097-4aad-a9fc-43bc0a411acd
has environmental constraint1 retained · stored CVE-2022-20821 → cisco · 821291f24159-6483-4d64-883d-bae3a975e7be
has environmental constraint1 retained · stored CVE-2022-20821 → cisco · ncs_10049338a215-a5a7-4713-b9e0-7be704844fd1
has environmental constraint1 retained · stored CVE-2022-20821 → cisco · ncs_55a2ce69a469-2442-4fc7-b901-8da5744ddd1c
has environmental constraint1 retained · stored CVE-2022-20821 → cisco · ncs-55a1-24q6h-scd0ffae4-b7dd-44aa-afc9-494a2955cb5e
has environmental constraint1 retained · stored CVE-2022-20821 → cisco · ncs-55a2-mod-s2d20ca55-95ed-4c7f-9069-748dca57280a
has environmental constraint1 retained · stored CVE-2022-20821 → cisco · ncs_5502-se0dde8a5d-06fc-4354-ace3-c154374d897a
has environmental constraint1 retained · stored CVE-2022-20821 → cisco · ncs_5501-sefaf59d0b-2800-4264-adbf-311e9929d01e
has environmental constraint1 retained · stored CVE-2022-20821 → cisco · ncs-55a2-mod-hx-s47f26199-43d1-4615-9513-2c3aa1973b50
has environmental constraint1 retained · stored CVE-2022-20821 → cisco · 82023c971ae9-3c6e-429a-8bd3-a6229c135cc7
has vulnerable target scope1 retained · stored CVE-2022-20821 → cisco · ios_xrecc4305b-6442-4124-8f1b-8f87cd4b9565