Port 3527Veritas Backup Exec Server

Veritas Backup Exec Server communications and message-queue traffic on TCP and UDP port 3527.

transport
tcp · udp

2 transports registered

in transit
cleartext

payload readable on path

assignment
official

registered with iana

risk
7/10

risk

lookups
0

rank 993 of 4,879 · top 20%

also known as beserver-msg-q

1 other service is registered on port 3527. compare all 2 →

Technical Details

what runs on :3527

Backup Exec uses proprietary communications over both TCP and UDP port 3527. The Backup Exec Server service uses the port for coordination and control traffic between backup-server components; UDP use is associated with service discovery or related server communications, while TCP carries established service exchanges. The protocol is not a general-purpose text protocol and does not provide an HTTP-style banner. Exact behavior varies by Backup Exec version and enabled components; TCP 10000 (Remote Agent) and port 6101 (Agent Browser) are commonly relevant when tracing a complete Backup Exec deployment.

Security Information

exposure of :3527

risk score

7/ 10risk

treat as sensitive. widely scanned and regularly exploited when reachable — restrict it to known sources.

system averages 2.7 across 922 ports — this one sits 4.3 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp · udp

udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite

security overview

This port should normally be restricted to trusted backup servers, protected hosts, and management networks, not exposed to the public internet. An exposed Backup Exec service increases the attack surface of backup infrastructure and may allow authenticated administrative operations or provide a path to sensitive backup data; historical product vulnerabilities also make version and patch management important. Use firewall allowlists and the product's supported authentication and encryption settings rather than relying on the port being obscure.

the 8 most looked-up other ports in system — 922 ports carry that label.

risk mix of the 8 listed

  • caution100%

0 of 8 encrypted