Evidence dossier

CVE-2022-20821

Cisco IOS XR Software Health Check Open Port Vulnerability

Exploited in the wild (CISA KEV since May 23, 2022). NVD reports CVSS 3.1 6.5. EPSS estimates 12.1% exploit likelihood as of Aug 27, 2026.

65.867.4Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

A vulnerability in the health check RPM of Cisco IOS XR Software could allow an unauthenticated, remote attacker to access the Redis instance that is running within the NOSi container. This vulnerability exists because the health check RPM opens TCP port 6379 by default upon activation. An attacker could exploit this vulnerability by connecting to the Redis instance on the open port. A successful exploit could allow the attacker to write to the Redis in-memory database, write arbitrary files to the container filesystem, and retrieve information about the Redis database. Given the configuration of the sandboxed container that the Redis instance runs in, a remote attacker would be unable to execute remote code or abuse the integrity of the Cisco IOS XR Software host system.

State
PUBLISHED
Published
May 26, 2022
Updated
Oct 21, 2025
Evidence coverage
92%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    cisco

    Record text: Cisco IOS XR Software Health Check Open Port Vulnerability

    Inspect raw assertion
    Field
    container
    Value
    Cisco IOS XR Software Health Check Open Port Vulnerability
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: Cisco IOS XR Open Port Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    Cisco IOS XR Open Port Vulnerability
    Original evidence ↗
  5. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 12.09% probability · 95.84th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.120940000000; percentile 0.958380000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date May 23, 2022 · first observed Jul 19, 2026

Exploit likelihood12.09%

FIRST EPSS · score date Aug 27, 2026 · 95.8th percentile · first observed Aug 27, 2026

SeverityCVSS 6.5

NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

casca-unknown-reasons-v1
Exploitation statusEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Exploit likelihoodEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Severity assessmentEvidence supported

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Aug 27, 2026
Resolution
None
Affected productsSource-reported scope

The cited source assertion is retained while canonical product linkage remains open.

Revision
casca-factor-d-obligations-v1
Cutoff
Aug 27, 2026
Resolution
Resolve identity

Source comparison

Who said what

CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
ciscoOriginal assertion
Record text

Cisco IOS XR Software Health Check Open Port Vulnerability

Inspect raw assertion
Field
container
Value
Cisco IOS XR Software Health Check Open Port Vulnerability
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

Cisco IOS XR Open Port Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
Cisco IOS XR Open Port Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

12.09% probability · 95.84th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.120940000000; percentile 0.958380000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
28Underlying assertions
28Canonical products
1Target assertions
27Constraint assertions

Grouped from 2 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

29 scope groups

cisco · source assertedCiscoCisco IOS XR SoftwareDirect source scope
Affected: n/a
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "n/a"}]
NVD CPE · HARDWAREcisco8201Environmental constraint · 1 assertions
Version not applicableCanonical identity product-1e1bb10dad49d6f6550690a24768b63711e714e55733248bb5bbabef770b540aLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:cisco:8201:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3d8e7fff-82a8-4ecb-ba0c-cbf0c2fda3a3
NVD CPE · HARDWAREcisco8202Environmental constraint · 1 assertions
Version not applicableCanonical identity product-feec29b9619c08f912fc982cbbb1ba1b23bd1de9a41641f783f9a1e07c000cafLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:cisco:8202:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    87dc4c2f-01c5-4d89-8d79-e5d28edad0f2
NVD CPE · HARDWAREcisco8208Environmental constraint · 1 assertions
Version not applicableCanonical identity product-91b8869a9309a80c8fbbcc7ac640403549802b62c78668c9e59a61d5ba11c1ecLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:cisco:8208:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a34dad43-0c95-4830-8078-efe3e6c0a930
NVD CPE · HARDWAREcisco8212Environmental constraint · 1 assertions
Version not applicableCanonical identity product-c00e65120cbce40f6d0f96c96c23d89e4c4705489dabbe7e63987b4427ea11bcLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:cisco:8212:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    46f5cbf0-7f55-44c0-b321-896bdba22679
NVD CPE · HARDWAREcisco8218Environmental constraint · 1 assertions
Version not applicableCanonical identity product-63b7df23d80bf0d5f82f3949eca3de0ef9bd0c663eeb4e65247942d290e318f1Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:cisco:8218:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d381e343-416f-42af-a780-d330954f238f
NVD CPE · OPERATING SYSTEMciscoios_xrVulnerable target · 1 assertions
Version not applicableCanonical identity product-a70ec7fc7d464008f2ddd19bcef52a09c444f9b0cbe4a0ab86461995673f4a82Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:cisco:ios_xr:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    92587aa0-bdb6-4594-8f14-dc2a91fa4cd6
NVD CPE · HARDWAREcisconcs_1001Environmental constraint · 1 assertions
Version not applicableCanonical identity product-5f445b2969e0110bbf03d99116339eaf5ca03b9cf4b6579c3ad9a755bba8081aLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:cisco:ncs_1001:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 15
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0f6e0fbe-70b7-413c-8943-39befe050298
NVD CPE · HARDWAREcisconcs_1002Environmental constraint · 1 assertions
Version not applicableCanonical identity product-62187a6fe2ea7936e1b134d4e2f80855cdc130468a376cee2c3f4247c398fc28Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:cisco:ncs_1002:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 16
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    37ae5fb0-d9a6-4ebe-9f7f-243299ae918b
NVD CPE · HARDWAREcisconcs_1004Environmental constraint · 1 assertions
Version not applicableCanonical identity product-c5173f456cc1b5360d4041a8e02b9a7eaebe804729c231286f7a17e060424e36Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:cisco:ncs_1004:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 17
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    60c9aaf8-4c5b-4ef5-b575-8235f3c54bcc
NVD CPE · HARDWAREcisconcs_5001Environmental constraint · 1 assertions
Version not applicableCanonical identity product-a8dc8298703ca024617c9e775b06313bf19386881864b2e679d04dc5e69cdbdaLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:cisco:ncs_5001:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 18
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e2a8c028-107b-4410-bcc6-5bcb8db63603
NVD CPE · HARDWAREcisconcs_5002Environmental constraint · 1 assertions
Version not applicableCanonical identity product-8c591f686029016ea7a0526d99c75cee38e4aee61c1fc66526061f75abb3864bLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:cisco:ncs_5002:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 19
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    da13fe67-f4ae-46df-921b-3fb91bdf742b
NVD CPE · HARDWAREcisconcs_5501-seEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-f4567789f7415b8ad2218d2105e5bedd09b1e1a07a0ba5359d2b7c286e1e75d1Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:cisco:ncs_5501-se:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 20
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1b254955-c485-45d7-a19b-e78ce1d997ad
NVD CPE · HARDWAREcisconcs_5502-seEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-e51fa7f44e28fe60f471463b9ee4167fcb3f0d5737ad755080ee7de076940ff1Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:cisco:ncs_5502-se:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 21
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    50c7b71a-2559-4e90-baaa-c6faafe35fc3
NVD CPE · HARDWAREcisconcs_5504Environmental constraint · 1 assertions
Version not applicableCanonical identity product-2593ed26ece06e79d46ea17073a345f2e73849db887612e2e0f0d2b9fe3da575Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:cisco:ncs_5504:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 22
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6ac4e089-296d-4c19-bf21-ddf2501dd77c
NVD CPE · HARDWAREcisconcs_5508Environmental constraint · 1 assertions
Version not applicableCanonical identity product-0586a95719cae35fa8096de2f1786d7bc46b0f8196dd416f60b518d96e3fe0c8Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:cisco:ncs_5508:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 23
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    43d21b01-a754-474f-8e46-14d733ab307e
NVD CPE · HARDWAREcisconcs_5516Environmental constraint · 1 assertions
Version not applicableCanonical identity product-36236c791722e74a97bb9d06d82b55f3119997e8f0df0c8b72ae59188120d961Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:cisco:ncs_5516:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 24
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    17d6424c-972f-459c-b8f7-04ffd9f541bc
NVD CPE · HARDWAREcisconcs_55a1Environmental constraint · 1 assertions
Version not applicableCanonical identity product-af3472e505e9626de9aac2c38fc1f2d284f05e134cf94d110c9d483b65bd98ebLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:cisco:ncs_55a1:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 25
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b51897cc-4fbf-4c99-bb69-2c528e392fe7
NVD CPE · HARDWAREcisconcs-55a1-24hEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-4c7ac95a19a680e20519bb3c0c20b150a4d8664a0918a1e23d3c4746bcb1cc79Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:cisco:ncs-55a1-24h:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d8d61548-61b4-4b53-8574-9db92b00a627
NVD CPE · HARDWAREcisconcs-55a1-24q6h-sEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-ce888184857a4f7f6459eea001f9a6a19a0188542868b82b474b08db77b31bfaLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:cisco:ncs-55a1-24q6h-s:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    74c8e3c6-282b-4394-a077-df8694f7e55d
NVD CPE · HARDWAREcisconcs-55a1-36h-sEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-b5cf327e066561afbc976092a5e1ea90009247d790ed9c05ca6fc29224723becLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:cisco:ncs-55a1-36h-s:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4ff08faf-67dd-4361-947a-40d5938db8ba
NVD CPE · HARDWAREcisconcs-55a1-36h-seEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-5a5fbc539620490d3e3716e613304da1a532a5754cb2c3390667d8da829d4cbbLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:cisco:ncs-55a1-36h-se:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1ce2ad36-5d52-4489-aac1-a7ac1b3d2581
NVD CPE · HARDWAREcisconcs-55a1-36h-se-sEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-486aa842a89b8cc6170253dc58c226944ef806e1d6fcc36a0aa5ba7e48d757eaLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:cisco:ncs-55a1-36h-se-s:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    14e948cf-9891-4ac8-8734-9c121b611722
NVD CPE · HARDWAREcisconcs_55a2Environmental constraint · 1 assertions
Version not applicableCanonical identity product-cb8a3928a7de2324e0439d57736e09ba69ff318d9308fb8445f81cbba5432f59Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:cisco:ncs_55a2:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 26
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    63ed034e-5a46-44a8-9101-8acd6d334ff5
NVD CPE · HARDWAREcisconcs-55a2-mod-hd-sEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-06cc6884e8d5a4e3945bf5247269ffc5c9f677d1e3fae5ef9ee380d22d9c0936Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:cisco:ncs-55a2-mod-hd-s:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 10
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a95fea95-703b-44e0-a7ca-9e38b2eb1980

Affected-product evidence

Accepted scope and product mapping

1 canonical links · 1 source-reported links

Mapping establishedEvidence supported

vendor-0774b265c0e837e737aaf99ed0f2450c048e61f34267ca59d8623878b839334e · product-a70ec7fc7d464008f2ddd19bcef52a09c444f9b0cbe4a0ab86461995673f4a82

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
ecc4305b-6442-4124-8f1b-8f87cd4b9565
Source-reported scopeSource-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Vendor specified only by source · Product specified only by source

Source class
Direct cve affected
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
ae23ae2c-1337-4742-91ca-61abf8523587

Assessments

CVSS by origin

6.5
NVDCVSS 3.1 · role Primary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
6.4
NVDCVSS 2.0 · role Primary · priority eligiblevalid_matchAV:N/AC:L/Au:N/C:P/I:P/A:N
6.5
psirt@cisco.comCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
6.5
ciscoCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Direct CVE/CNA normalized decisions

6.5Priority eligible

cisco

CVSS 3.1 · Primary · Original assertion · rank 1

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Validation
Valid match
Recomputed
6.5
Decision reason
Evidence supported
Policy
casca-direct-cvss-eligibility-v1

Assessments are retained side by side under closed precedence. Cascade never averages CVSS.

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.