Port 4369: Erlang Port Mapper Daemon
EPMD is the name server for distributed Erlang: nodes register with it on TCP 4369 and peers ask it which port each node uses for distribution traffic. RabbitMQ and Apache CouchDB use EPMD on 4369 by default. RabbitMQ lists 4369 together with 25672 for inter-node and CLI tool communication.
Port Details
Security Exposure
Shadowserver found around 116,000 EPMD instances accessible from the internet in 2022 and notes that access can sometimes be exploitable, citing Apache CouchDB CVE-2022-24706. EPMD lists registered node names and their distribution ports. Erlang's documentation states that node communication is cleartext by default, that the cookie mechanism is not cryptographically secure, and that starting a distributed node without -proto_dist inet_tls exposes it to attacks that may give complete access to the node and the cluster.
Hardening
- +Firewall TCP 4369 and the Erlang distribution port range so only cluster members and administration hosts can reach them.
- +Use TLS for Erlang distribution (-proto_dist inet_tls) where nodes communicate across untrusted networks.
- +Set a long random Erlang cookie instead of a default or guessable value.
- +Bind EPMD to specific addresses with ERL_EPMD_ADDRESS; it always listens on the loopback address as well.
Monitoring
Alert on connections to 4369 or 25672 from hosts outside the cluster. Shadowserver reports for an organization's networks flag EPMD services visible from the internet.
EPMD Vulnerabilities
1 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2022-24706 | Remote Code Execution Vulnerability in Packaging | Apache Software Foundation | 9.8 | 92.5% | KEV | 2022-04-26 |
Tools for Auditing and Monitoring EPMD
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
OPENVAS
Free / CommercialFull-featured vulnerability scanner for identifying security flaws, missing patches, and weak configs across network hosts.
Nessus
CommercialTenable vulnerability scanner with the industry’s largest plugin library; time-limited free Essentials license.
Related Tool Categories
Frequently Asked Questions
What is port 4369?→
TCP 4369 is the default port of the Erlang Port Mapper Daemon (EPMD), which maps Erlang node names to distribution ports. RabbitMQ and CouchDB use it.
Should port 4369 be exposed to the internet?→
No. Shadowserver states that it is unlikely an EPMD server needs external connections and recommends firewalling it.
Can the EPMD port be changed?→
Yes. The ERL_EPMD_PORT environment variable or the -port option changes it, and all hosts in a cluster must use the same port.
Which vulnerabilities affect the service on port 4369?→
This database lists 1 CVE related to EPMD, 1 of them confirmed as exploited by CISA. Examples: CVE-2022-24706.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 4369 is not guaranteed to be EPMD. Exploited-in-the-wild data from the CISA KEV catalog (CC0).