Port 1900SSDP / UPnP Discovery

Port 1900 is primarily used by the Simple Service Discovery Protocol (SSDP), which is a part of the Universal Plug and Play (UPnP) suite of protocols. It facilitates the discovery of network devices and services on local networks without the need for manual configuration, enabling seamless interoperability among diverse devices such as printers, smart TVs, media servers, and IoT devices..

transport
udp

single transport

in transit
cleartext

payload readable on path

assignment
official

registered with iana

risk
4/10

caution

lookups
14,613

rank 231 of 993 · top 23%

Technical Details

what runs on :1900

The Simple Service Discovery Protocol (SSDP) operates over UDP port 1900 to enable automatic discovery of UPnP devices within a local network. Devices broadcast NOTIFY messages and respond to M-SEARCH requests to advertise or discover services. SSDP uses a multicast address (239.255.255.250) to efficiently reach multiple devices simultaneously.

This discovery mechanism allows consumer devices to announce capabilities dynamically, such as media streaming features or printer availability, without user intervention. Control points, such as smartphones or computers, can then browse these devices and interact with their services using standardized protocols.

Despite facilitating plug-and-play ease on home and small office networks, SSDP is limited by its lack of authentication and plaintext communications, making it susceptible to various network abuses. Its reliance on multicast traffic also means excessive or misconfigured devices can generate substantial broadcast traffic, affecting network performance.

Security Information

exposure of :1900

risk score

4/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

network services averages 3.9 across 604 ports — this one sits 0.1 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

udp

udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite

security overview

Common Vulnerabilities:

  • SSDP lacks authentication mechanisms, making it vulnerable to spoofing or unauthorized access.
  • Openly exposed SSDP services can be exploited in amplification Distributed Denial of Service (DDoS) attacks, where attackers send forged requests causing target devices to flood a victim with traffic.
  • SSDP servers exposed to the internet can leak sensitive network topology information, aiding reconnaissance by attackers.

Common Mitigations:

  • Block or restrict UDP port 1900 at the network perimeter to prevent external exploitation.
  • Disable UPnP on devices and routers where it's unnecessary, especially on edge devices.
  • Regularly update firmware on networking equipment to patch known vulnerabilities.
  • Use network segmentation to limit the broadcast domain of SSDP traffic.
  • Employ firewall rules or intrusion prevention systems to detect and block suspicious SSDP traffic patterns.

the 8 most looked-up other ports in network services — 604 ports carry that label.

risk mix of the 8 listed

  • caution100%

0 of 8 encrypted