Impact
A vulnerability in the Thinkst Canary honeypot Redis service allows an unauthenticated remote attacker to trigger a denial‑of‑service attack by sending specially crafted requests to the Redis service. The flaw exists only when the Redis service is enabled and can be abused without any authentication. The impact is a disruption of the Canary’s ability to collect telemetry, effectively disabling the honeypot for the affected instance.
Affected Systems
The vulnerable product is Thinkst Canary across all supported platforms, including AWS EC2, Docker, GCP, Hardware, Microsoft Azure, Microsoft Hyper‑V, Nutanix, OCI, OpenStack, Tailscale, and VMware ESXi. Versions before the patched releases listed in the vendor advisory are affected; for example, on the AWS EC2 platform versions 2.0.2 through the pre‑patch 5.3.1 are vulnerable. All other platforms have comparable vulnerable ranges as specified in the advisory.
Risk and Exploitability
The CVSS score of 3.7 indicates a medium severity attack, and the vulnerability is not listed in CISA KEV, implying no publicly known exploits. The EPSS score is not available; based on the lack of authentication requirement and the ubiquitous nature of the Redis service, it is inferred that an attacker with network access could exploit the flaw by sending arbitrary commands. Based on the description, the resulting denial of service could disrupt threat monitoring for security teams. The risk is moderate given the medium severity, but the operational impact of a DoS to a honeypot may be significant for environments relying on continuous monitoring.
OpenCVE Enrichment