Skip to main content

Port Details

Port
6379
Transport
TCP
Service
Redis
IANA service name
redis
Range
User port (1024-49151)

Security Exposure

Redis documentation states it is designed for trusted clients in trusted environments and should not be exposed to the internet. An open instance can be wiped with a single FLUSHALL command. Shadowserver reports Redis instances accessible without authentication as high severity, and a Debian-specific Lua sandbox escape (CVE-2022-0543) is in the CISA KEV catalog.

Hardening

  • +Bind Redis to loopback or a private interface and firewall 6379 from untrusted networks.
  • +Leave protected mode enabled. Since version 3.2.0, Redis started with the default configuration (binding all interfaces) and no password only answers on the loopback interface.
  • +Use ACL users with limited commands, or at least requirepass.
  • +Enable TLS for connections that cross hosts.
  • +Restrict dangerous commands such as CONFIG with ACL rules, which Redis now recommends over the deprecated rename-command method.

Monitoring

Watch for client connections from unexpected addresses, failed AUTH attempts and use of administrative commands such as CONFIG or FLUSHALL.

Redis Vulnerabilities

1 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2022-0543
Debian-specific Redis Server Lua Sandbox Escape Vulnerability
Debian10.099.4%KEV2022-02-18

Tools for Auditing and Monitoring Redis

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Nuclei

Free / Commercial
Vulnerability Scanning

Fast vulnerability scanner powered by community YAML templates to scan web applications, networks, and cloud targets for known defects.

LicenseMIT
PlatformLinux, macOS, Windows

Shodan

Freemium
Open Source Intelligence Tools

Search engine for Internet-connected devices that indexes service banners, open ports, and exposed assets across public IP space.

LicenseProprietary (service); MIT (Python client)
PlatformWeb, Linux, macOS, Windows

Frequently Asked Questions

Is Redis safe to expose on port 6379?→

No. Redis documentation says it is designed for trusted environments and that it is usually not a good idea to expose it to the internet.

What is Redis protected mode?→

Since Redis 3.2.0, an instance with the default bind setting and no password only answers on loopback and returns an error to other clients.

Which vulnerabilities affect the service on port 6379?→

This database lists 1 CVE related to Redis, 1 of them confirmed as exploited by CISA. Examples: CVE-2022-0543.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 6379 is not guaranteed to be Redis. Exploited-in-the-wild data from the CISA KEV catalog (CC0).