Rewterz

Rewterz Threat Alert – Eternity Project – Malware Being Sold Via Telegram – Active IOCs

May 23, 2022
Rewterz

Rewterz Threat Alert – Sugar Ransomware – Active IOCs

May 23, 2022

Rewterz Threat Advisory – CVE-2022-20821 – Cisco IOS XR Vulnerability

Severity

Medium

Analysis Summary

CVE-2022-20821

Cisco IOS XR could allow a remote attacker to bypass security restrictions, caused by an issue the health check RPM opening TCP port 6379 by default upon activation. By connecting to the Redis instance on the open port, an attacker could exploit this vulnerability to write to the Redis in-memory database, write arbitrary files to the container filesystem, and retrieve information about the Redis database.

Impact

  • Security Bypass

Indicators Of Compromise

CVE

  • CVE-2022-20821

Affected Vendors

  • Cisco

Affected Products

  • Cisco IOS XR 7.3.3

Remediation

Refer to Cisco Security Advisory for patch, upgrade or suggested workaround information.

Cisco Security Advisory

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.