Port 6379: Redis key-value store
Port 6379 is the IANA-registered TCP port for Redis, which IANA describes as an advanced key-value cache and store. IANA reserves UDP 6379.
Port Details
Security Exposure
Redis documentation states it is designed for trusted clients in trusted environments and should not be exposed to the internet. An open instance can be wiped with a single FLUSHALL command. Shadowserver reports Redis instances accessible without authentication as high severity, and a Debian-specific Lua sandbox escape (CVE-2022-0543) is in the CISA KEV catalog.
Hardening
- +Bind Redis to loopback or a private interface and firewall 6379 from untrusted networks.
- +Leave protected mode enabled. Since version 3.2.0, Redis started with the default configuration (binding all interfaces) and no password only answers on the loopback interface.
- +Use ACL users with limited commands, or at least requirepass.
- +Enable TLS for connections that cross hosts.
- +Restrict dangerous commands such as CONFIG with ACL rules, which Redis now recommends over the deprecated rename-command method.
Monitoring
Watch for client connections from unexpected addresses, failed AUTH attempts and use of administrative commands such as CONFIG or FLUSHALL.
Redis Vulnerabilities
1 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2022-0543 | Debian-specific Redis Server Lua Sandbox Escape Vulnerability | Debian | 10.0 | 99.4% | KEV | 2022-02-18 |
Tools for Auditing and Monitoring Redis
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Nuclei
Free / CommercialFast vulnerability scanner powered by community YAML templates to scan web applications, networks, and cloud targets for known defects.
Shodan
FreemiumSearch engine for Internet-connected devices that indexes service banners, open ports, and exposed assets across public IP space.
Related Tool Categories
Data loss prevention, data posture management, and sensitive data discovery and classification platforms.
Zero trust access, secure web gateways, firewalls, and perimeter enforcement platforms.
Infrastructure scanners, CVE audit engines, container image inspectors, and exposure management platforms.
Frequently Asked Questions
Is Redis safe to expose on port 6379?→
No. Redis documentation says it is designed for trusted environments and that it is usually not a good idea to expose it to the internet.
What is Redis protected mode?→
Since Redis 3.2.0, an instance with the default bind setting and no password only answers on loopback and returns an error to other clients.
Which vulnerabilities affect the service on port 6379?→
This database lists 1 CVE related to Redis, 1 of them confirmed as exploited by CISA. Examples: CVE-2022-0543.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 6379 is not guaranteed to be Redis. Exploited-in-the-wild data from the CISA KEV catalog (CC0).