Port 19999DNP3 Secure
DNP3 Secure is an enhanced, secure version of the Distributed Network Protocol used primarily for communication between SCADA systems and devices like RTUs and IEDs. It adds robust authentication and encryption features to the standard DNP3, aiming to protect critical infrastructure communications from interception and tampering..
- transport
- unknown
- in transit
- cleartext
- assignment
- unofficial
- risk
- 4/10
- lookups
- 11,987
single transport
payload readable on path
used by convention
caution
rank 329 of 993 · top 33%
Technical Details
what runs on :19999Distributed Network Protocol version 3 (DNP3) is a widely adopted protocol in industrial automation and control systems, especially within utilities like electricity and water. The 'Secure' version introduces layered cryptographic protections to the traditional protocol, addressing the inherent security challenges of transmitting critical operational data.
DNP3 Secure incorporates measures like message authentication and data encryption to mitigate eavesdropping, spoofing, and replay attacks. It utilizes standards such as IEC 62351 to define cryptographic mechanisms, ensuring data integrity, confidentiality, and authentication between communicating devices including Remote Terminal Units (RTUs), Intelligent Electronic Devices (IEDs), and SCADA masters.
Typically, DNP3 Secure functions over TCP/IP or UDP, though this specific port (19999) might be used for proprietary or vendor-specific implementations. Its secure extensions are critical in protecting grid operation data and commands from cyber threats, promoting increased resilience within critical infrastructure.
Security Information
exposure of :19999risk score
4/ 10caution
worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.
security averages 3.8 across 216 ports — this one sits 0.2 above.
in transit
cleartext
credentials and payloads are readable by anyone on path
assignment
unofficial
used by convention, not registered — what answers here varies by deployment
reachable over
unknown
every listening transport is another surface to filter at the edge
security overview
Common Vulnerabilities:
- Misconfiguration leading to exposure without encryption or authentication
- Legacy devices falling back to insecure mode or using weak cipher suites
- Susceptibility to replay attacks if proper timestamps or counters aren't enforced
- Potential DoS targets due to unauthenticated message flooding
Mitigations:
- Ensure all nodes enforce DNP3 Secure extensions with strong, up-to-date cryptography
- Use network segmentation and firewalls to isolate SCADA networks
- Regularly update device firmware to patch security flaws
- Implement strict access controls and monitor network traffic for anomalies
- Conduct routine security audits and compliance checks with IEC 62351 guidelines
Related Ports
the 8 most looked-up other ports in security — 216 ports carry that label.
| port | service | risk | |||
|---|---|---|---|---|---|
| :8881 | Atlasz Secure Server | TCP | Web Services | caution | 67.6k |
| :443 | HTTPS | TCPtls | Web Services | caution | 65.9k |
| :8291 | Winbox MikroTik Admin | TCP | Security | caution | 62.9k |
| :3268 | Microsoft Global Catalog (GC) | TCPUDP | Security | caution | 54.6k |
| :135 | Microsoft EPMAP | TCPUDP | Security | caution | 51.9k |
| :3128 | Squid Proxy HTTP | TCP | Web Services | caution | 45.8k |
| :8080 | HTTP Alternate | TCPtls | Web Services | caution | 44.9k |
| :7000 | Vuze HTTPS Tracker | TCPtls | Security | caution | 28.9k |
risk mix of the 8 listed
- caution100%
3 of 8 encrypted