CISA KEV · catalog date May 23, 2022 · first observed Jul 19, 2026
Evidence dossier
CVE-2022-20821
Cisco IOS XR Software Health Check Open Port Vulnerability
Exploited in the wild (CISA KEV since May 23, 2022). NVD reports CVSS 3.1 6.5. EPSS estimates 12.1% exploit likelihood as of Aug 27, 2026.
As of Aug 27, 2026
Normalized restatement
A vulnerability in the health check RPM of Cisco IOS XR Software could allow an unauthenticated, remote attacker to access the Redis instance that is running within the NOSi container. This vulnerability exists because the health check RPM opens TCP port 6379 by default upon activation. An attacker could exploit this vulnerability by connecting to the Redis instance on the open port. A successful exploit could allow the attacker to write to the Redis in-memory database, write arbitrary files to the container filesystem, and retrieve information about the Redis database. Given the configuration of the sandboxed container that the Redis instance runs in, a remote attacker would be unable to execute remote code or abuse the integrity of the Cisco IOS XR Software host system.
- State
- PUBLISHED
- Published
- May 26, 2022
- Updated
- Oct 21, 2025
- Evidence coverage
- 92%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCAciscoOriginal evidence ↗
Record text: Cisco IOS XR Software Health Check Open Port Vulnerability
Inspect raw assertion
- Field
container- Value
- Cisco IOS XR Software Health Check Open Port Vulnerability
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Cisco IOS XR Open Port Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Cisco IOS XR Open Port Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 12.09% probability · 95.84th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.120940000000; percentile 0.958380000000
FIRST EPSS · score date Aug 27, 2026 · 95.8th percentile · first observed Aug 27, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
Cisco IOS XR Software Health Check Open Port Vulnerability
Inspect raw assertion
- Field
container- Value
- Cisco IOS XR Software Health Check Open Port Vulnerability
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
Cisco IOS XR Open Port Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Cisco IOS XR Open Port Vulnerability
12.09% probability · 95.84th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.120940000000; percentile 0.958380000000
Applicability
Cited product scope
Grouped from 2 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
29 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "n/a"}]product-1e1bb10dad49d6f6550690a24768b63711e714e55733248bb5bbabef770b540aLinked exactInspect raw assertion
cpe:2.3:h:cisco:8201:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3d8e7fff-82a8-4ecb-ba0c-cbf0c2fda3a3
product-feec29b9619c08f912fc982cbbb1ba1b23bd1de9a41641f783f9a1e07c000cafLinked exactInspect raw assertion
cpe:2.3:h:cisco:8202:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
87dc4c2f-01c5-4d89-8d79-e5d28edad0f2
product-91b8869a9309a80c8fbbcc7ac640403549802b62c78668c9e59a61d5ba11c1ecLinked exactInspect raw assertion
cpe:2.3:h:cisco:8208:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a34dad43-0c95-4830-8078-efe3e6c0a930
product-c00e65120cbce40f6d0f96c96c23d89e4c4705489dabbe7e63987b4427ea11bcLinked exactInspect raw assertion
cpe:2.3:h:cisco:8212:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
46f5cbf0-7f55-44c0-b321-896bdba22679
product-63b7df23d80bf0d5f82f3949eca3de0ef9bd0c663eeb4e65247942d290e318f1Linked exactInspect raw assertion
cpe:2.3:h:cisco:8218:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d381e343-416f-42af-a780-d330954f238f
product-a70ec7fc7d464008f2ddd19bcef52a09c444f9b0cbe4a0ab86461995673f4a82Linked exactInspect raw assertion
cpe:2.3:o:cisco:ios_xr:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
92587aa0-bdb6-4594-8f14-dc2a91fa4cd6
product-5f445b2969e0110bbf03d99116339eaf5ca03b9cf4b6579c3ad9a755bba8081aLinked exactInspect raw assertion
cpe:2.3:h:cisco:ncs_1001:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 15
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0f6e0fbe-70b7-413c-8943-39befe050298
product-62187a6fe2ea7936e1b134d4e2f80855cdc130468a376cee2c3f4247c398fc28Linked exactInspect raw assertion
cpe:2.3:h:cisco:ncs_1002:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 16
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
37ae5fb0-d9a6-4ebe-9f7f-243299ae918b
product-c5173f456cc1b5360d4041a8e02b9a7eaebe804729c231286f7a17e060424e36Linked exactInspect raw assertion
cpe:2.3:h:cisco:ncs_1004:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 17
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
60c9aaf8-4c5b-4ef5-b575-8235f3c54bcc
product-a8dc8298703ca024617c9e775b06313bf19386881864b2e679d04dc5e69cdbdaLinked exactInspect raw assertion
cpe:2.3:h:cisco:ncs_5001:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 18
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e2a8c028-107b-4410-bcc6-5bcb8db63603
product-8c591f686029016ea7a0526d99c75cee38e4aee61c1fc66526061f75abb3864bLinked exactInspect raw assertion
cpe:2.3:h:cisco:ncs_5002:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 19
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
da13fe67-f4ae-46df-921b-3fb91bdf742b
product-f4567789f7415b8ad2218d2105e5bedd09b1e1a07a0ba5359d2b7c286e1e75d1Linked exactInspect raw assertion
cpe:2.3:h:cisco:ncs_5501-se:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 20
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1b254955-c485-45d7-a19b-e78ce1d997ad
product-e51fa7f44e28fe60f471463b9ee4167fcb3f0d5737ad755080ee7de076940ff1Linked exactInspect raw assertion
cpe:2.3:h:cisco:ncs_5502-se:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 21
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
50c7b71a-2559-4e90-baaa-c6faafe35fc3
product-2593ed26ece06e79d46ea17073a345f2e73849db887612e2e0f0d2b9fe3da575Linked exactInspect raw assertion
cpe:2.3:h:cisco:ncs_5504:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 22
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6ac4e089-296d-4c19-bf21-ddf2501dd77c
product-0586a95719cae35fa8096de2f1786d7bc46b0f8196dd416f60b518d96e3fe0c8Linked exactInspect raw assertion
cpe:2.3:h:cisco:ncs_5508:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 23
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
43d21b01-a754-474f-8e46-14d733ab307e
product-36236c791722e74a97bb9d06d82b55f3119997e8f0df0c8b72ae59188120d961Linked exactInspect raw assertion
cpe:2.3:h:cisco:ncs_5516:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 24
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
17d6424c-972f-459c-b8f7-04ffd9f541bc
product-af3472e505e9626de9aac2c38fc1f2d284f05e134cf94d110c9d483b65bd98ebLinked exactInspect raw assertion
cpe:2.3:h:cisco:ncs_55a1:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 25
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b51897cc-4fbf-4c99-bb69-2c528e392fe7
product-4c7ac95a19a680e20519bb3c0c20b150a4d8664a0918a1e23d3c4746bcb1cc79Linked exactInspect raw assertion
cpe:2.3:h:cisco:ncs-55a1-24h:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d8d61548-61b4-4b53-8574-9db92b00a627
product-ce888184857a4f7f6459eea001f9a6a19a0188542868b82b474b08db77b31bfaLinked exactInspect raw assertion
cpe:2.3:h:cisco:ncs-55a1-24q6h-s:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
74c8e3c6-282b-4394-a077-df8694f7e55d
product-b5cf327e066561afbc976092a5e1ea90009247d790ed9c05ca6fc29224723becLinked exactInspect raw assertion
cpe:2.3:h:cisco:ncs-55a1-36h-s:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4ff08faf-67dd-4361-947a-40d5938db8ba
product-5a5fbc539620490d3e3716e613304da1a532a5754cb2c3390667d8da829d4cbbLinked exactInspect raw assertion
cpe:2.3:h:cisco:ncs-55a1-36h-se:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1ce2ad36-5d52-4489-aac1-a7ac1b3d2581
product-486aa842a89b8cc6170253dc58c226944ef806e1d6fcc36a0aa5ba7e48d757eaLinked exactInspect raw assertion
cpe:2.3:h:cisco:ncs-55a1-36h-se-s:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
14e948cf-9891-4ac8-8734-9c121b611722
product-cb8a3928a7de2324e0439d57736e09ba69ff318d9308fb8445f81cbba5432f59Linked exactInspect raw assertion
cpe:2.3:h:cisco:ncs_55a2:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 26
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
63ed034e-5a46-44a8-9101-8acd6d334ff5
product-06cc6884e8d5a4e3945bf5247269ffc5c9f677d1e3fae5ef9ee380d22d9c0936Linked exactInspect raw assertion
cpe:2.3:h:cisco:ncs-55a2-mod-hd-s:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a95fea95-703b-44e0-a7ca-9e38b2eb1980
Affected-product evidence
Accepted scope and product mapping
1 canonical links · 1 source-reported links
vendor-0774b265c0e837e737aaf99ed0f2450c048e61f34267ca59d8623878b839334e · product-a70ec7fc7d464008f2ddd19bcef52a09c444f9b0cbe4a0ab86461995673f4a82
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
ecc4305b-6442-4124-8f1b-8f87cd4b9565Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
ae23ae2c-1337-4742-91ca-61abf8523587Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:NAV:N/AC:L/Au:N/C:P/I:P/A:NCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:NCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:NDirect CVE/CNA normalized decisions
cisco
CVSS 3.1 · Primary · Original assertion · rank 1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N- Validation
- Valid match
- Recomputed
- 6.5
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.