Port 3702WS-Discovery

Web Services Dynamic Discovery (WS-Discovery) is a multicast discovery protocol primarily used in Windows environments for detecting network devices and services dynamically. It enables automatic service discovery without manual configuration, facilitating efficient communication between devices such as printers, cameras, and other network-enabled appliances..

transport
tcp · udp

2 transports registered

in transit
cleartext

payload readable on path

assignment
official

registered with iana

risk
4/10

caution

lookups
16,472

rank 177 of 993 · top 18%

Technical Details

what runs on :3702

Web Services Dynamic Discovery (WS-Discovery) is a technical specification defined by the OASIS standards body, designed to facilitate the dynamic discovery of network services over a local multicast IP network. It operates over UDP and TCP on port 3702, using SOAP-over-UDP messages for communication. WS-Discovery enables devices to discover each other automatically by exchanging multicast probe and resolve messages.

The protocol plays a crucial role in zero-configuration networking, especially in Windows environments and embedded devices that support web services. Devices announce their presence through multicast 'Hello' messages and send 'Bye' when they become unavailable. Clients can also actively search for specific services using probe messages broadcast to the network.

While it is widely supported in the Microsoft ecosystem, WS-Discovery has applications beyond, including Internet of Things (IoT) implementations and enterprise environments where seamless device integration and automatic detection reduce administrative overhead.

Security Information

exposure of :3702

risk score

4/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

network services averages 3.9 across 604 ports — this one sits 0.1 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp · udp

udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite

security overview

Common vulnerabilities involving WS-Discovery include:

  • Exploitation of unauthenticated message handling, leading to information disclosure or unauthorized service enumeration.
  • Amplification attacks where malicious actors send spoofed requests to numerous devices, triggering overwhelming response traffic toward a victim (DDoS reflection).
  • Exposure of sensitive network topology information to untrusted parties due to improper segmentation or insecure multicast configurations.

Mitigations include:

  • Restricting WS-Discovery traffic using VLAN segmentation and network access controls to limit multicast range.
  • Implementing firewall rules to block inbound and outbound WS-Discovery traffic on untrusted interfaces.
  • Monitoring WS-Discovery activity for unusual volume or origin, which may indicate reconnaissance or amplification attacks.
  • Disabling WS-Discovery on devices where it is not necessary, reducing network exposure.
  • Keeping all networked service devices updated to address known protocol handling vulnerabilities.

the 8 most looked-up other ports in network services — 604 ports carry that label.

risk mix of the 8 listed

  • caution100%

0 of 8 encrypted