Port 2369BMC Control-M Configuration Agent
Port 2369 is the default communication port used by the BMC Software Control-M/Server Configuration Agent. This port facilitates configuration updates, management tasks, and orchestration control for Control-M's workload automation components. It is typically used during initial setup and ongoing system management, but administrators often change the default port as part of security hardening..
- transport
- tcp
- in transit
- cleartext
- assignment
- official
- risk
- 4/10
- lookups
- 14,805
single transport
payload readable on path
registered with iana
caution
rank 224 of 993 · top 22%
Technical Details
what runs on :2369Technical Overview:
BMC's Control-M is a robust enterprise workload automation tool allowing centralized scheduling and management of batch processing. The Configuration Agent, operating by default over port 2369, acts as an intermediary to manage agent communications, configuration commands, deployment updates, and status retrieval. This facilitates seamless integration between the Control-M Server and distributed agents deployed throughout the infrastructure.
Port Role and Operation:
Port 2369 typically listens on the Control-M/Server or Control-M Agents. It utilizes TCP for reliable, ordered data delivery required in configuration management exchanges. As a management interface, it handles agent registration, configuration sync, and status reporting. While not handling job output transfer or scheduling data directly, it remains essential for coordination.
Deployment Considerations:
During installation, administrators may customize this port to comply with their internal network policies or security practices. Firewalls should be configured accordingly to permit legitimate communications only, and careful change management is advised when altering this port to avoid disruption.
Security Information
exposure of :2369risk score
4/ 10caution
worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.
system averages 3.9 across 342 ports — this one sits 0.1 above.
in transit
cleartext
credentials and payloads are readable by anyone on path
assignment
official
registered with iana for this service — scanners fingerprint it by number
reachable over
tcp
every listening transport is another surface to filter at the edge
security overview
Common Vulnerabilities:
- Unauthorized access if default port remains unchanged and accessible externally
- Lack of encryption by default, exposing configuration data to interception
- Potential exploitation of Control-M service vulnerabilities to gain privileged access or disrupt workloads
- Possible abuse for lateral movement if attackers compromise exposed agents
Common Mitigations:
- Change the default port during installation to an uncommon, non-default value
- Strictly limit network access through firewalls and ACLs to trusted management networks
- Utilize VPNs or secure tunnels to protect management traffic
- Regularly patch BMC Control-M software to fix security flaws
- Monitor connection attempts for suspicious activity
- Enable encryption on management interfaces if the environment supports it
- Implement role-based access controls and authentication to restrict administrative actions
Related Ports
the 8 most looked-up other ports in system — 342 ports carry that label.
| port | service | risk | |||
|---|---|---|---|---|---|
| :8888 | Sun Answerbook & Alt HTTP | TCP | Web Services | caution | 123.9k |
| :4664 | Google Desktop Search | TCP | System | caution | 67.2k |
| :8008 | IBM HTTP Server Admin | TCP | Web Services | caution | 58.3k |
| :3268 | Microsoft Global Catalog (GC) | TCPUDP | Security | caution | 54.6k |
| :135 | Microsoft EPMAP | TCPUDP | Security | caution | 51.9k |
| :9080 | WebSphere HTTP Transport (default) | TCP | Web Services | caution | 51.6k |
| :23 | Telnet | TCP | Remote Access | caution | 34.8k |
| :12489 | NSClient Monitoring Agent | TCP | Network Services | caution | 30.0k |
risk mix of the 8 listed
- caution100%
0 of 8 encrypted