Port 3000: Grafana web UI and common development HTTP servers
TCP 3000 has no single standard service. Grafana's http_port setting defaults to 3000, and many web framework examples, such as the Express hello world app, listen on 3000. IANA's registrations for the port (hbci and remoteware-cl) are unrelated to these common uses.
Port Details
Security Exposure
Applications on 3000 are often dashboards or development servers. Grafana's default admin_user and admin_password are both admin, set on first run, and the default Grafana Admin has full permissions, so a reachable instance with an unchanged password is fully exposed. Grafana strongly recommends changing the default administrator password.
Hardening
- +Change Grafana's admin_password before first start, or immediately after, and remove unused local accounts.
- +Put Grafana behind a reverse proxy with TLS and single sign-on instead of exposing port 3000 directly.
- +Bind development servers to localhost and do not publish them through firewalls or cloud security groups.
- +Keep Grafana updated and review its security advisories.
Monitoring
Inventory hosts listening on 3000 and confirm each one has an owner and authentication. For Grafana, confirm the default admin password was changed and review which users hold administrator rights.
Grafana / dev servers Vulnerabilities
2 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2021-43798 | Grafana path traversal | grafana | 7.5 | 88.5% | KEV | 2021-12-07 |
| CVE-2021-39226 | Snapshot authentication bypass in grafana | grafana | 9.8 | 99.9% | KEV | 2021-10-05 |
Tools for Auditing and Monitoring Grafana / dev servers
ZAP
Open SourceOpen-source web application security scanner and intercepting proxy for detecting web flaws during development and testing.
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Nuclei
Free / CommercialFast vulnerability scanner powered by community YAML templates to scan web applications, networks, and cloud targets for known defects.
Related Tool Categories
Frequently Asked Questions
What uses port 3000?→
Grafana listens on 3000 by default, and many Node.js examples, including the Express hello world app, use it as a development port. IANA's assignments for 3000 are unrelated.
What is the default Grafana login?→
Grafana's configuration reference lists admin as the default admin_user and admin as the default admin_password, set on first run.
How do I change the Grafana port?→
Set http_port in the [server] section of the Grafana configuration file. Binding to port 80 requires extra privileges, as the Grafana docs explain.
Which vulnerabilities affect the service on port 3000?→
This database lists 2 CVEs related to Grafana / dev servers, 2 of them confirmed as exploited by CISA. Examples: CVE-2021-43798, CVE-2021-39226.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 3000 is not guaranteed to be Grafana / dev servers. Exploited-in-the-wild data from the CISA KEV catalog (CC0).