Port 902VMware Console UDP

UDP port 902 is primarily used by VMware Server Console for communication between the managed VMware server and the management console. It enables important service functions like remote management, control, and monitoring of virtual infrastructure, ensuring administrators can maintain oversight of VMware environments efficiently through network communications..

transport
udp

single transport

in transit
cleartext

payload readable on path

assignment
unofficial

used by convention

risk
4/10

caution

lookups
28,015

rank 47 of 993 · top 5%

3 other services are registered on port 902. compare all 4

Technical Details

what runs on :902

UDP port 902 is a critical communication channel used predominantly in VMware virtualization environments. It facilitates management traffic between VMware ESXi hosts and the VMware vSphere Client or other management tools. This port is often engaged when remote desktop sessions or console access to virtual machines (VMs) are initiated, thereby enabling administrators to control VMs from a distance seamlessly.

The VMware Server Console or vSphere Client communicates to the ESXi host using UDP 902 to exchange control commands and status updates. Such interaction allows functions including VM power management, console access, and monitoring. The reliance on UDP is due to its lower overhead, which speeds up console responsiveness but also means that communication is connectionless and less reliable.

Beyond standard management, port 902 is also involved in certain data transfer processes, like provisioning new VMs or migrating them between hosts when using features such as vMotion in conjunction with other ports. Its use is internal within VMware’s management architecture, but it is critical for maintaining the operational efficiency of the virtualized infrastructure.

Security Information

exposure of :902

risk score

4/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

remote access averages 4.0 across 110 ports — this one sits level with it.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

unofficial

used by convention, not registered — what answers here varies by deployment

reachable over

udp

udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite

security overview

Common Vulnerabilities:

  • Open UDP port 902 can expose the VMware environment to unauthorized access if network-level security is weak or default configurations are retained.
  • Because UDP is connectionless, it is susceptible to spoofing and reflection attacks, potentially providing an avenue for denial of service (DoS) attacks.
  • Improperly segmented management networks may allow malicious actors within the organization to exploit this port to gain control or interfere with VM management.

Common Mitigations:

  • Implement strict network segmentation so port 902 is accessible only from trusted management subnets while blocked from user or external networks.
  • Use firewall rules to restrict traffic to known management IP addresses.
  • Enable role-based access controls within VMware to limit privileges related to console access.
  • Monitor network activity for unusual access or traffic patterns to this port as an indication of possible attacks.
  • Where supported, encapsulate or secure management communications using SSL/TLS to reduce risks associated with cleartext data transfer, even if encryption is not default on UDP 902.

the 8 most looked-up other ports in remote access — 110 ports carry that label.

risk mix of the 8 listed

  • safe13%
  • caution88%

0 of 8 encrypted