Port 2967Symantec AV Corporate

Port 2967 is primarily used by Symantec AntiVirus Corporate Edition to facilitate client-server communication within enterprise environments. It enables the transfer of virus definitions, policy updates, and reporting data between managed clients and Symantec management servers. Keeping this port accessible is essential for maintaining updated antivirus protection and centralized security management across corporate networks..

transport
tcp

single transport

in transit
cleartext

payload readable on path

assignment
unofficial

used by convention

risk
4/10

caution

lookups
5,857

rank 843 of 993 · top 85%

Technical Details

what runs on :2967

Port 2967 is mainly associated with client-server communications of Symantec AntiVirus Corporate Edition (SAVCE). It is used by the Symantec Management Console to distribute virus definitions, security policies, and software updates to endpoint clients managed within an enterprise network, ensuring consistent protection.

This port facilitates real-time status reporting and alerting from endpoints back to the central Symantec server. This bidirectional communication allows administrators to monitor infection statuses, trigger scans, and enforce compliance policies across all deployed machines without manual intervention.

Typically, the port relies on a proprietary protocol developed by Symantec, running over TCP. Since it's not officially standardized by IANA, this port usage is considered unofficial and primarily proprietary, meaning other vendors do not commonly use this port assignment.

Security Information

exposure of :2967

risk score

4/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

security averages 3.8 across 216 ports — this one sits 0.2 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

unofficial

used by convention, not registered — what answers here varies by deployment

reachable over

tcp

every listening transport is another surface to filter at the edge

security overview

Symantec AntiVirus Corporate Edition communications over port 2967 may be susceptible to several vulnerabilities:

  • Unauthorized access: If exposed beyond trusted network boundaries or improperly segmented, attackers could potentially impersonate clients or servers, intercept update data, or inject malicious configurations.
  • Man-in-the-middle (MitM) attacks: Without proper encryption or authentication, communications could be intercepted or altered.
  • Exploitation of management services: Attackers may attempt to exploit vulnerabilities in the management console or update mechanisms to gain control over endpoint security or disrupt protection.

Mitigations include:

  • Restricting port 2967 access to internal, trusted subnets via firewall rules to prevent external exposure.
  • Implementing strong authentication mechanisms and, where possible, enabling encryption to protect data in transit.
  • Regularly updating and patching Symantec products to mitigate known vulnerabilities.
  • Monitoring network traffic to detect anomalies or suspicious activities targeting this port.
  • Enforcing the principle of least privilege, ensuring only authorized devices communicate via this port.

the 8 most looked-up other ports in security — 216 ports carry that label.

risk mix of the 8 listed

  • caution100%

3 of 8 encrypted