Port 1900SSDP / UPnP Discovery
Port 1900 is primarily used by the Simple Service Discovery Protocol (SSDP), which is a part of the Universal Plug and Play (UPnP) suite of protocols. It facilitates the discovery of network devices and services on local networks without the need for manual configuration, enabling seamless interoperability among diverse devices such as printers, smart TVs, media servers, and IoT devices..
- transport
- udp
- in transit
- cleartext
- assignment
- official
- risk
- 4/10
- lookups
- 14,613
single transport
payload readable on path
registered with iana
caution
rank 231 of 993 · top 23%
Technical Details
what runs on :1900The Simple Service Discovery Protocol (SSDP) operates over UDP port 1900 to enable automatic discovery of UPnP devices within a local network. Devices broadcast NOTIFY messages and respond to M-SEARCH requests to advertise or discover services. SSDP uses a multicast address (239.255.255.250) to efficiently reach multiple devices simultaneously.
This discovery mechanism allows consumer devices to announce capabilities dynamically, such as media streaming features or printer availability, without user intervention. Control points, such as smartphones or computers, can then browse these devices and interact with their services using standardized protocols.
Despite facilitating plug-and-play ease on home and small office networks, SSDP is limited by its lack of authentication and plaintext communications, making it susceptible to various network abuses. Its reliance on multicast traffic also means excessive or misconfigured devices can generate substantial broadcast traffic, affecting network performance.
Security Information
exposure of :1900risk score
4/ 10caution
worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.
network services averages 3.9 across 604 ports — this one sits 0.1 above.
in transit
cleartext
credentials and payloads are readable by anyone on path
assignment
official
registered with iana for this service — scanners fingerprint it by number
reachable over
udp
udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite
security overview
Common Vulnerabilities:
- SSDP lacks authentication mechanisms, making it vulnerable to spoofing or unauthorized access.
- Openly exposed SSDP services can be exploited in amplification Distributed Denial of Service (DDoS) attacks, where attackers send forged requests causing target devices to flood a victim with traffic.
- SSDP servers exposed to the internet can leak sensitive network topology information, aiding reconnaissance by attackers.
Common Mitigations:
- Block or restrict UDP port 1900 at the network perimeter to prevent external exploitation.
- Disable UPnP on devices and routers where it's unnecessary, especially on edge devices.
- Regularly update firmware on networking equipment to patch known vulnerabilities.
- Use network segmentation to limit the broadcast domain of SSDP traffic.
- Employ firewall rules or intrusion prevention systems to detect and block suspicious SSDP traffic patterns.
Related Ports
the 8 most looked-up other ports in network services — 604 ports carry that label.
| port | service | risk | |||
|---|---|---|---|---|---|
| :9080 | Groove RPC | TCPUDP | Web Services | caution | 70.8k |
| :6543 | Jetnet | UDP | Network Services | caution | 65.3k |
| :5938 | TeamViewer | TCPUDP | Remote Access | caution | 65.0k |
| :8291 | Winbox MikroTik Admin | TCP | Security | caution | 62.9k |
| :3233 | WhiskerControl Protocol | TCPUDP | Network Services | caution | 61.9k |
| :3268 | Microsoft Global Catalog (GC) | TCPUDP | Security | caution | 54.6k |
| :135 | Microsoft EPMAP | TCPUDP | Security | caution | 51.9k |
| :3128 | Tatsoft Default HTTP Proxy | TCP | Web Services | caution | 46.8k |
risk mix of the 8 listed
- caution100%
0 of 8 encrypted