Back to Database
Status published
Medium
CVE-2023-28425
Specially crafted MSETNX command can lead to denial-of-service
Vulnerability Description
Redis is an in-memory database that persists on disk. Starting in version 7.0.8 and prior to version 7.0.10, authenticated users can use the MSETNX command to trigger a runtime assertion and termination of the Redis server process. The problem is fixed in Redis version 7.0.10.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-28425
Credits & Attribution
No credits recorded in the NVD database.
References
More from redis
View All →CVE-2025-62507
Redis: Bug in XACKDEL may lead to stack overflow and potential RCE
High
7.7
CVE-2025-49844
Redis Lua Use-After-Free may lead to remote code execution
Critical
10
CVE-2025-48367
Redis DoS Vulnerability due to bad connection error handling
High
7.5
CVE-2025-46819
Redis is vulnerable to DoS via specially crafted LUA scripts
Medium
6.3
CVE-2025-46818
Redis: Authenticated users can execute LUA scripts as a different user
Medium
6
Affected Vendor
redis
View all reports →Affected Software
redis
Vulnerable Versions:
>= 7.0.8, < 7.0.10
Timeline
Official Publish:
March 20th, 2023
Last Modified:
February 25th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H