Port 2945Megaco H.248

Megaco H.248 over port 2945 uses ASN.1 binary encoding to facilitate signaling commands for multimedia gateway control. It enables communication between call control elements and media gateways, supporting various media types within large VoIP and multimedia networks. It plays a vital role in managing complex media streaming and telephony services across distributed networks..

transport
udp · sctp

2 transports registered

in transit
cleartext

payload readable on path

assignment
unofficial

used by convention

risk
4/10

caution

lookups
8,081

rank 628 of 993 · top 63%

Technical Details

what runs on :2945

The Megaco (H.248) protocol is a standardized signaling protocol used in Voice over Internet Protocol (VoIP) and multimedia communications. It facilitates communication between a Media Gateway Controller (call agent) and Media Gateways that handle media conversion between circuit-switched networks and packet-switched networks. Port 2945 is allocated for the binary encoding of Megaco messages using ASN.1, which provides a compact and efficient data representation.

Megaco enables endpoints or media streams to be created, modified, and deleted dynamically, supporting a wide range of signaling scenarios including multimedia conferencing, VoIP calls, and interactive media services. It supports control over media stream functions such as codec selection, echo cancellation, and tone generation. The use of ASN.1 enhances interoperability among heterogeneous systems by adhering to ITU-T and IETF standards.

This protocol operates primarily over UDP on port 2945, though some implementations may use TCP or SCTP for increased reliability. However, official assignments primarily stipulate UDP use. Megaco is inherently scalable, designed for environments such as carrier-grade switching networks, large enterprise telephony, and IP multimedia subsystems where managing media gateways is necessary.

Security Information

exposure of :2945

risk score

4/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

network services averages 3.9 across 604 ports — this one sits 0.1 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

unofficial

used by convention, not registered — what answers here varies by deployment

reachable over

udp · sctp

udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite

security overview

Common Vulnerabilities

  • Lack of Encryption: Since Megaco over port 2945 typically lacks native encryption, signaling data can be intercepted or altered via man-in-the-middle attacks.
  • Spoofing Attacks: Attackers can forge control commands, potentially disrupting media gateways or hijacking sessions.
  • Denial of Service (DoS): Flooding gateway controllers with malformed or excessive Megaco messages can disrupt service availability.
  • Protocol Parsing Bugs: Implementation errors in ASN.1 decoding might be exploited for remote code execution or service crashes.

Common Mitigations

  • Use IPsec or TLS: Encapsulate Megaco signaling within encrypted transport layers to ensure confidentiality and integrity.
  • Strict Access Controls: Employ strong authentication and network segmentation to restrict who can access management channels.
  • Firewall Filtering: Limit traffic on port 2945 to trusted hosts via firewalls or ACLs.
  • Input Validation: Update and patch gateways regularly to fix protocol parsing vulnerabilities and improve resilience against malformed packets.
  • Monitoring and Logging: Continuously monitor signaling traffic for abnormal patterns indicating abuse or ongoing attacks.

the 8 most looked-up other ports in network services — 604 ports carry that label.

risk mix of the 8 listed

  • caution100%

0 of 8 encrypted