Description
CDB uses 3306 as the default MySQL intranet port. Using the default is not itself a vulnerability, and changing it does not replace authentication or network access controls.
Potential impact
Loose access controls can permit unwanted database connection attempts regardless of the port number.
Remediation
Set intranet_port according to operational policy and restrict permitted clients. If changing the port, update application connections and security group rules together.
Examples
These excerpts change the intranet port from 3306 to 3307 and omit other instance settings. The port change alone does not establish security.
Before
hcl
resource "tencentcloud_mysql_instance" "example" {
instance_name = "tf-example-mysql"
mem_size = 4000
volume_size = 200
intranet_port = 3306
security_groups = [tencentcloud_security_group.security_group.id]
}
After
hcl
resource "tencentcloud_mysql_instance" "example" {
instance_name = "tf-example-mysql"
mem_size = 4000
volume_size = 200
intranet_port = 3307
security_groups = [tencentcloud_security_group.security_group.id]
}