Port 901VMware VI Client

Port 901 is primarily used by the VMware Virtual Infrastructure (VI) Client, which facilitates management communication between VMware ESX/ESXi servers and the management interface. It often serves the connection flow from servers being managed back to the console, enabling user access to virtualization controls and management features..

transport
tcp

single transport

in transit
cleartext

payload readable on path

assignment
unofficial

used by convention

risk
4/10

caution

lookups
7,784

rank 659 of 993 · top 66%

1 other service is registered on port 901. compare all 2

Technical Details

what runs on :901
  • VMware Virtual Infrastructure Client, also known as vSphere Client in later iterations, connects administrators to VMware vCenter Server or directly to ESX/ESXi hypervisors, allowing centralized management and configuration.

  • Port 901 is commonly associated with VMware’s proprietary Remote Console functionality and can be used for server-initiated communication, such as event or status updates to the client console. While TCP 902 is widely known for VM console traffic, port 901 may facilitate additional management features.

  • This port ties into the ecosystem of VMware’s virtualization solutions, where networked management traffic must remain isolated and controlled to maintain separation between guest, host, and administrative domains. It generally operates over unencrypted channels by default, increasing the importance of network segmentation.

Security Information

exposure of :901

risk score

4/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

network services averages 3.9 across 604 ports — this one sits 0.1 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

unofficial

used by convention, not registered — what answers here varies by deployment

reachable over

tcp

every listening transport is another surface to filter at the edge

security overview

  • Common Vulnerabilities:

    • If exposed externally, port 901 may be targeted for unauthorized access, exploitation of management interfaces, or man-in-the-middle (MitM) attacks.
    • Absence of encryption can expose sensitive management data and credentials during transit.
    • Misconfiguration could allow lateral movement by attackers within a compromised network segment.
  • Mitigations:

    • Restrict access to port 901 via firewall rules, limiting connectivity only to trusted administrative hosts.
    • Implement role-based access controls within VMware to minimize potential misuse.
    • Use VPNs or secure management networks to encrypt management traffic when possible.
    • Regularly update VMware infrastructure to patch vulnerabilities, and disable unnecessary legacy services relying on this port.

the 8 most looked-up other ports in network services — 604 ports carry that label.

risk mix of the 8 listed

  • caution100%

0 of 8 encrypted