Port 6640Open vSwitch Database (OVSDB)

Open vSwitch uses OVSDB to manage switch configuration and state over JSON-RPC on TCP port 6640.

transport
tcp

single transport

in transit
cleartext

payload readable on path

assignment
official

registered with iana

risk
8/10

risk

lookups
0

rank 993 of 5,749 · top 17%

also known as RFC 7047

Technical Details

what runs on :6640

OVSDB is the database management protocol specified in RFC 7047. It runs over TCP and exchanges UTF-8 JSON-RPC messages, framed as newline-terminated JSON objects; there is no separate protocol handshake before JSON-RPC requests. Clients can discover schemas and databases, monitor changes, and submit transactions to read or modify records. TCP port 6640 is the conventional plaintext endpoint; deployments may use TLS on port 6641 instead.

Security Information

exposure of :6640

risk score

8/ 10risk

treat as sensitive. widely scanned and regularly exploited when reachable — restrict it to known sources.

databases averages 3.8 across 152 ports — this one sits 4.2 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp

every listening transport is another surface to filter at the edge

security overview

This is a switch-management database interface: a client with sufficient access can inspect or change network configuration, including bridges, ports, and controller settings. Plain TCP on 6640 is not encrypted and OVSDB has no built-in password exchange, so do not expose it to untrusted networks; restrict reachability and use TLS with appropriate client authentication and access controls where remote management is needed.

the 8 most looked-up other ports in databases — 152 ports carry that label.

risk mix of the 8 listed

  • caution100%

1 of 8 encrypted