Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2022-20821
Cisco IOS XR Software Health Check Open Port Vulnerability
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U L L N 6.5 .1147 95.9 YES
AFFECTED
Product Versions Fixed
Cisco IOS XR Software n/a – —
TIMELINE
Nov 2 Reserved by cisco
May 23 Added to CISA KEV, remediation due 2022-06-13
May 26 Published (CNA: cisco)
Description
A vulnerability in the health check RPM of Cisco IOS XR Software could allow an unauthenticated, remote attacker to access the Redis instance that is running within the NOSi container. This vulnerability exists because the health check RPM opens TCP port 6379 by default upon activation. An attacker could exploit this vulnerability by connecting to the Redis instance on the open port. A successful exploit could allow the attacker to write to the Redis in-memory database, write arbitrary files to the container filesystem, and retrieve information about the Redis database. Given the configuration of the sandboxed container that the Redis instance runs in, a remote attacker would be unable to execute remote code or abuse the integrity of the Cisco IOS XR Software host system.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| November 2, 2021 | Reserved | Reserved by cisco |
| May 23, 2022 | KEV ADDED | Added to CISA KEV, remediation due 2022-06-13 |
| May 26, 2022 | Published | Published (CNA: cisco) |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Cisco | Cisco IOS XR Software | — | n/a | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2022-20821 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.