Vulnerability Intelligence

🛡 CVE-2022-20821

Cisco IOS XR Open Port Vulnerability
Cisco IOS XR CWE-923

Ransomware use

CISA KEV

EPSS

11.8%
Elevated · 96th pct

Added to KEV

2022-05-23
CISA

Remediate by

2022-06-13
⚠ OVERDUE

CWE

CWE-923
weakness

📈 EPSS exploit probability

11.8%
FIRST EPSS — 30-day probability of exploitation in the wild · band Elevated · higher than 96% of all scored CVEs

⚠ KEV remediation overdue

CISA required federal remediation by 2022-06-13. This exploited vulnerability is past its Binding Operational Directive 22-01 due date — prioritize patch/mitigation and hunt for exploitation.

📄 Description

Cisco IOS XR software health check opens TCP port 6379 by default on activation. An attacker can connect to the Redis instance on the open port and allow access to the Redis instance that is running within the NOSi container.

🛡 Add to case

Attach CVE-2022-20821 (Vulnerability / CVE) and pull all linked entities:
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php