← Vulnerability feed

Vulnerability record · CVE-2023-28425 · published 20 March 2023

CVE-2023-28425: Redis MSETNX command triggers assertion and server termination

Redis · Redis

Redis versions 7.0.8 through 7.0.9 allow an authenticated user to issue the MSETNX command in a way that trips a runtime assertion, killing the server process. Because Redis is often a shared, long-lived service, a single authenticated client can take the whole instance down. The flaw is fixed in 7.0.10.

5.5 CVSS 3.1 Medium EPSS 55% · top 1.0% CWE-77 · Command injectionCWE-617 · CWE-617
5.5CVSS 3.1 base score
55%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

Redis is an in-memory database that persists on disk. Starting in version 7.0.8 and prior to version 7.0.10, authenticated users can use the MSETNX command to trigger a runtime assertion and termination of the Redis server process. The problem is fixed in Redis version 7.0.10.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

medium priorityThe flaw is an authenticated local denial of service with no confidentiality or integrity impact, but the high EPSS score and ease of triggering warrant prompt patching.

What it is

Redis versions 7.0.8 through 7.0.9 allow an authenticated user to issue the MSETNX command in a way that trips a runtime assertion, killing the server process. Because Redis is often a shared, long-lived service, a single authenticated client can take the whole instance down. The flaw is fixed in 7.0.10.

Impact

An attacker with valid credentials gains denial of service against the Redis server, terminating the process and disrupting all applications and users relying on that instance. There is no data confidentiality or integrity impact per the CVSS vector.

Attack surface

Reached locally per the CVSS vector (AV:L), meaning the attacker needs a position on the host or an equivalent local access path to the Redis service. Authentication is required (PR:L) and no user interaction is needed (UI:N).

Exploitation

Not listed in CISA KEV and no public exploit references are tagged in the record, but EPSS is high at roughly 0.55 (99th percentile), indicating elevated predicted exploitation activity.

What to do

  • Upgrade Redis to 7.0.10 or later, which contains the fix in commit 48e0d478.
  • If immediate upgrade is not possible, restrict access to the Redis port and require strong authentication so only trusted clients can issue commands.
  • Audit and limit which accounts hold command execution rights, and disable or rename MSETNX where feasible.
  • Monitor Redis process restarts and unexpected terminations as a signal of attempted or successful exploitation.
  • Track vendor advisories, including the NetApp advisory, for downstream product exposure.

Detection

  • Alert on Redis process crashes or restarts correlated with MSETNX command usage in logs or slowlog.
  • Search Redis command logs or audit trails for MSETNX calls from unexpected clients or accounts.
  • Monitor for repeated connection and command patterns from a single authenticated user preceding a server termination.
  • Baseline normal Redis uptime and flag abrupt shutdowns without an administrative restart.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-28425 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2022-0543Debian-packaged Redis Lua sandbox escape allows remote code executionA Debian-specific packaging flaw in Redis leaves the Lua interpreter's sandbox improperly restricted, allowing escape from the Lua sandbox. Because R…KEVEPSS 99%analysed9.9CVE-2025-49844Redis Lua scripting use-after-free enables remote code executionRedis versions 8.2.1 and below contain a use-after-free in the Lua scripting engine. An authenticated user can supply a crafted Lua script that manip…EPSS 82%analysed9.8CVE-2025-27151Redis improper input validation vulnerabilityRedis is an open source, in-memory database that persists on disk. In versions starting from 7.0.0 to before 8.0.2, a stack-based buffer overflow exi…EPSS 0.95%9.8CVE-2024-46981Redis use after free vulnerabilityRedis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to manipulate the gar…EPSS 8.2%9.8CVE-2022-3734Redis untrusted search path vulnerabilityA vulnerability was found in a port or fork of Redis. It has been declared as critical. This vulnerability affects unknown code in the library C:/Pro…EPSS 0.65%9.8CVE-2022-35951Redis integer overflow vulnerabilityRedis is an in-memory database that persists on disk. Versions 7.0.0 and above, prior to 7.0.5 are vulnerable to an Integer Overflow. Executing an `X…EPSS 3.9%8.8CVE-2025-46817Redis integer overflow vulnerabilityRedis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lu…EPSS 3.8%8.8CVE-2024-31449Redis improper input validation vulnerabilityRedis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to trigger a stack bu…EPSS 4.5%

Source: NIST National Vulnerability Database (record CVE-2023-28425), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.