Port 3702WS-Discovery
Web Services Dynamic Discovery (WS-Discovery) is a multicast discovery protocol primarily used in Windows environments for detecting network devices and services dynamically. It enables automatic service discovery without manual configuration, facilitating efficient communication between devices such as printers, cameras, and other network-enabled appliances..
- transport
- tcp · udp
- in transit
- cleartext
- assignment
- official
- risk
- 4/10
- lookups
- 16,472
2 transports registered
payload readable on path
registered with iana
caution
rank 177 of 993 · top 18%
Technical Details
what runs on :3702Web Services Dynamic Discovery (WS-Discovery) is a technical specification defined by the OASIS standards body, designed to facilitate the dynamic discovery of network services over a local multicast IP network. It operates over UDP and TCP on port 3702, using SOAP-over-UDP messages for communication. WS-Discovery enables devices to discover each other automatically by exchanging multicast probe and resolve messages.
The protocol plays a crucial role in zero-configuration networking, especially in Windows environments and embedded devices that support web services. Devices announce their presence through multicast 'Hello' messages and send 'Bye' when they become unavailable. Clients can also actively search for specific services using probe messages broadcast to the network.
While it is widely supported in the Microsoft ecosystem, WS-Discovery has applications beyond, including Internet of Things (IoT) implementations and enterprise environments where seamless device integration and automatic detection reduce administrative overhead.
Security Information
exposure of :3702risk score
4/ 10caution
worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.
network services averages 3.9 across 604 ports — this one sits 0.1 above.
in transit
cleartext
credentials and payloads are readable by anyone on path
assignment
official
registered with iana for this service — scanners fingerprint it by number
reachable over
tcp · udp
udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite
security overview
Common vulnerabilities involving WS-Discovery include:
- Exploitation of unauthenticated message handling, leading to information disclosure or unauthorized service enumeration.
- Amplification attacks where malicious actors send spoofed requests to numerous devices, triggering overwhelming response traffic toward a victim (DDoS reflection).
- Exposure of sensitive network topology information to untrusted parties due to improper segmentation or insecure multicast configurations.
Mitigations include:
- Restricting WS-Discovery traffic using VLAN segmentation and network access controls to limit multicast range.
- Implementing firewall rules to block inbound and outbound WS-Discovery traffic on untrusted interfaces.
- Monitoring WS-Discovery activity for unusual volume or origin, which may indicate reconnaissance or amplification attacks.
- Disabling WS-Discovery on devices where it is not necessary, reducing network exposure.
- Keeping all networked service devices updated to address known protocol handling vulnerabilities.
Related Ports
the 8 most looked-up other ports in network services — 604 ports carry that label.
| port | service | risk | |||
|---|---|---|---|---|---|
| :9080 | Groove RPC | TCPUDP | Web Services | caution | 70.8k |
| :6543 | Jetnet | UDP | Network Services | caution | 65.3k |
| :5938 | TeamViewer | TCPUDP | Remote Access | caution | 65.0k |
| :8291 | Winbox MikroTik Admin | TCP | Security | caution | 62.9k |
| :3233 | WhiskerControl Protocol | TCPUDP | Network Services | caution | 61.9k |
| :3268 | Microsoft Global Catalog (GC) | TCPUDP | Security | caution | 54.6k |
| :135 | Microsoft EPMAP | TCPUDP | Security | caution | 51.9k |
| :3128 | Tatsoft Default HTTP Proxy | TCP | Web Services | caution | 46.8k |
risk mix of the 8 listed
- caution100%
0 of 8 encrypted