Vulnerability record · CVE-2023-28425 · published 20 March 2023
CVE-2023-28425: Redis MSETNX command triggers assertion and server termination
Redis · Redis
Redis versions 7.0.8 through 7.0.9 allow an authenticated user to issue the MSETNX command in a way that trips a runtime assertion, killing the server process. Because Redis is often a shared, long-lived service, a single authenticated client can take the whole instance down. The flaw is fixed in 7.0.10.
Description
Redis is an in-memory database that persists on disk. Starting in version 7.0.8 and prior to version 7.0.10, authenticated users can use the MSETNX command to trigger a runtime assertion and termination of the Redis server process. The problem is fixed in Redis version 7.0.10.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Automated analysis
medium priorityThe flaw is an authenticated local denial of service with no confidentiality or integrity impact, but the high EPSS score and ease of triggering warrant prompt patching.
What it is
Redis versions 7.0.8 through 7.0.9 allow an authenticated user to issue the MSETNX command in a way that trips a runtime assertion, killing the server process. Because Redis is often a shared, long-lived service, a single authenticated client can take the whole instance down. The flaw is fixed in 7.0.10.
Impact
An attacker with valid credentials gains denial of service against the Redis server, terminating the process and disrupting all applications and users relying on that instance. There is no data confidentiality or integrity impact per the CVSS vector.
Attack surface
Reached locally per the CVSS vector (AV:L), meaning the attacker needs a position on the host or an equivalent local access path to the Redis service. Authentication is required (PR:L) and no user interaction is needed (UI:N).
Exploitation
Not listed in CISA KEV and no public exploit references are tagged in the record, but EPSS is high at roughly 0.55 (99th percentile), indicating elevated predicted exploitation activity.
What to do
- Upgrade Redis to 7.0.10 or later, which contains the fix in commit 48e0d478.
- If immediate upgrade is not possible, restrict access to the Redis port and require strong authentication so only trusted clients can issue commands.
- Audit and limit which accounts hold command execution rights, and disable or rename MSETNX where feasible.
- Monitor Redis process restarts and unexpected terminations as a signal of attempted or successful exploitation.
- Track vendor advisories, including the NetApp advisory, for downstream product exposure.
Detection
- Alert on Redis process crashes or restarts correlated with MSETNX command usage in logs or slowlog.
- Search Redis command logs or audit trails for MSETNX calls from unexpected clients or accounts.
- Monitor for repeated connection and command patterns from a single authenticated user preceding a server termination.
- Baseline normal Redis uptime and flag abrupt shutdowns without an administrative restart.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-28425 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-28425), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.