Skip to main content

Port Details

Port
4369
Transport
TCP
Service
EPMD
IANA service name
epmd
Range
User port (1024-49151)
Related ports
2567256725671

Security Exposure

Shadowserver found around 116,000 EPMD instances accessible from the internet in 2022 and notes that access can sometimes be exploitable, citing Apache CouchDB CVE-2022-24706. EPMD lists registered node names and their distribution ports. Erlang's documentation states that node communication is cleartext by default, that the cookie mechanism is not cryptographically secure, and that starting a distributed node without -proto_dist inet_tls exposes it to attacks that may give complete access to the node and the cluster.

Hardening

  • +Firewall TCP 4369 and the Erlang distribution port range so only cluster members and administration hosts can reach them.
  • +Use TLS for Erlang distribution (-proto_dist inet_tls) where nodes communicate across untrusted networks.
  • +Set a long random Erlang cookie instead of a default or guessable value.
  • +Bind EPMD to specific addresses with ERL_EPMD_ADDRESS; it always listens on the loopback address as well.

Monitoring

Alert on connections to 4369 or 25672 from hosts outside the cluster. Shadowserver reports for an organization's networks flag EPMD services visible from the internet.

EPMD Vulnerabilities

1 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2022-24706
Remote Code Execution Vulnerability in Packaging
Apache Software Foundation9.892.5%KEV2022-04-26

Tools for Auditing and Monitoring EPMD

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

OPENVAS

Free / Commercial
Vulnerability Scanning

Full-featured vulnerability scanner for identifying security flaws, missing patches, and weak configs across network hosts.

LicenseGPL-2.0-only (C scanner); GPL-2.0-or-later WITH OpenSSL-exception (Rust)
PlatformLinux

Nessus

Commercial
Vulnerability Scanning

Tenable vulnerability scanner with the industry’s largest plugin library; time-limited free Essentials license.

LicenseProprietary
PlatformLinux, Windows, Web

Frequently Asked Questions

What is port 4369?→

TCP 4369 is the default port of the Erlang Port Mapper Daemon (EPMD), which maps Erlang node names to distribution ports. RabbitMQ and CouchDB use it.

Should port 4369 be exposed to the internet?→

No. Shadowserver states that it is unlikely an EPMD server needs external connections and recommends firewalling it.

Can the EPMD port be changed?→

Yes. The ERL_EPMD_PORT environment variable or the -port option changes it, and all hosts in a cluster must use the same port.

Which vulnerabilities affect the service on port 4369?→

This database lists 1 CVE related to EPMD, 1 of them confirmed as exploited by CISA. Examples: CVE-2022-24706.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 4369 is not guaranteed to be EPMD. Exploited-in-the-wild data from the CISA KEV catalog (CC0).