Port 2967Symantec AV Corporate
Port 2967 is primarily used by Symantec AntiVirus Corporate Edition to facilitate client-server communication within enterprise environments. It enables the transfer of virus definitions, policy updates, and reporting data between managed clients and Symantec management servers. Keeping this port accessible is essential for maintaining updated antivirus protection and centralized security management across corporate networks..
- transport
- tcp
- in transit
- cleartext
- assignment
- unofficial
- risk
- 4/10
- lookups
- 5,857
single transport
payload readable on path
used by convention
caution
rank 843 of 993 · top 85%
Technical Details
what runs on :2967Port 2967 is mainly associated with client-server communications of Symantec AntiVirus Corporate Edition (SAVCE). It is used by the Symantec Management Console to distribute virus definitions, security policies, and software updates to endpoint clients managed within an enterprise network, ensuring consistent protection.
This port facilitates real-time status reporting and alerting from endpoints back to the central Symantec server. This bidirectional communication allows administrators to monitor infection statuses, trigger scans, and enforce compliance policies across all deployed machines without manual intervention.
Typically, the port relies on a proprietary protocol developed by Symantec, running over TCP. Since it's not officially standardized by IANA, this port usage is considered unofficial and primarily proprietary, meaning other vendors do not commonly use this port assignment.
Security Information
exposure of :2967risk score
4/ 10caution
worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.
security averages 3.8 across 216 ports — this one sits 0.2 above.
in transit
cleartext
credentials and payloads are readable by anyone on path
assignment
unofficial
used by convention, not registered — what answers here varies by deployment
reachable over
tcp
every listening transport is another surface to filter at the edge
security overview
Symantec AntiVirus Corporate Edition communications over port 2967 may be susceptible to several vulnerabilities:
- Unauthorized access: If exposed beyond trusted network boundaries or improperly segmented, attackers could potentially impersonate clients or servers, intercept update data, or inject malicious configurations.
- Man-in-the-middle (MitM) attacks: Without proper encryption or authentication, communications could be intercepted or altered.
- Exploitation of management services: Attackers may attempt to exploit vulnerabilities in the management console or update mechanisms to gain control over endpoint security or disrupt protection.
Mitigations include:
- Restricting port 2967 access to internal, trusted subnets via firewall rules to prevent external exposure.
- Implementing strong authentication mechanisms and, where possible, enabling encryption to protect data in transit.
- Regularly updating and patching Symantec products to mitigate known vulnerabilities.
- Monitoring network traffic to detect anomalies or suspicious activities targeting this port.
- Enforcing the principle of least privilege, ensuring only authorized devices communicate via this port.
Related Ports
the 8 most looked-up other ports in security — 216 ports carry that label.
| port | service | risk | |||
|---|---|---|---|---|---|
| :8881 | Atlasz Secure Server | TCP | Web Services | caution | 67.6k |
| :443 | HTTPS | TCPtls | Web Services | caution | 65.9k |
| :8291 | Winbox MikroTik Admin | TCP | Security | caution | 62.9k |
| :3268 | Microsoft Global Catalog (GC) | TCPUDP | Security | caution | 54.6k |
| :135 | Microsoft EPMAP | TCPUDP | Security | caution | 51.9k |
| :3128 | Squid Proxy HTTP | TCP | Web Services | caution | 45.8k |
| :8080 | HTTP Alternate | TCPtls | Web Services | caution | 44.9k |
| :7000 | Vuze HTTPS Tracker | TCPtls | Security | caution | 28.9k |
risk mix of the 8 listed
- caution100%
3 of 8 encrypted