Skip to content

Redis Unauthenticated Access Detection

redis-unauthenticated-access is a critical severity check in the databases category, written in yaml. Its source is templates/databases/redis/redis-unauthenticated.yaml in cert-x-gen-templates.

Detects Redis instances exposed without authentication (requirepass disabled). Unauthenticated Redis allows arbitrary command execution and data exfiltration.

This template tests the Redis protocol directly on port 6379 (or 6380 for replicas). For Redis exporter detection, use the ‘redis-exporter-exposed’ template.

PROTOCOL FLEXIBILITY:

  • Uses ‘network: protocol: tcp’ for direct Redis protocol testing
  • Engine automatically detects supported protocol: TCP
  • Recommended ports: 6379 (default), 6380 (replica)
Field Value
Id redis-unauthenticated-access
Severity critical
Language yaml
Category databases
Author CERT-X-GEN Security Team
Template version not recorded
Confidence 95
CVSS not recorded
Weakness CWE-306
Tags redis, unauthenticated, database, nosql, cache, network
Target kind not recorded
Oracle not recorded

The file declares extractors, network, remediation as well. Those are not tabled above; read the source for what they carry.

Declared in the header. cxg parses @references and then discards it, and nothing at scan time reads it, so this is the only place the links a template cites are surfaced.

To see what the copy on your machine says about itself, and to confirm it is installed at all:

Terminal window
cxg template info redis-unauthenticated-access

The id it prints is the one to pass anywhere a template is selected. See cxg template for the rest of the subcommand, Scan a target for running a scan, and A match is not a finding for how to read what comes back.