Port 902VMware Console UDP
UDP port 902 is primarily used by VMware Server Console for communication between the managed VMware server and the management console. It enables important service functions like remote management, control, and monitoring of virtual infrastructure, ensuring administrators can maintain oversight of VMware environments efficiently through network communications..
- transport
- udp
- in transit
- cleartext
- assignment
- unofficial
- risk
- 4/10
- lookups
- 28,015
single transport
payload readable on path
used by convention
caution
rank 47 of 993 · top 5%
3 other services are registered on port 902. compare all 4 →
Technical Details
what runs on :902UDP port 902 is a critical communication channel used predominantly in VMware virtualization environments. It facilitates management traffic between VMware ESXi hosts and the VMware vSphere Client or other management tools. This port is often engaged when remote desktop sessions or console access to virtual machines (VMs) are initiated, thereby enabling administrators to control VMs from a distance seamlessly.
The VMware Server Console or vSphere Client communicates to the ESXi host using UDP 902 to exchange control commands and status updates. Such interaction allows functions including VM power management, console access, and monitoring. The reliance on UDP is due to its lower overhead, which speeds up console responsiveness but also means that communication is connectionless and less reliable.
Beyond standard management, port 902 is also involved in certain data transfer processes, like provisioning new VMs or migrating them between hosts when using features such as vMotion in conjunction with other ports. Its use is internal within VMware’s management architecture, but it is critical for maintaining the operational efficiency of the virtualized infrastructure.
Security Information
exposure of :902risk score
4/ 10caution
worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.
remote access averages 4.0 across 110 ports — this one sits level with it.
in transit
cleartext
credentials and payloads are readable by anyone on path
assignment
unofficial
used by convention, not registered — what answers here varies by deployment
reachable over
udp
udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite
security overview
Common Vulnerabilities:
- Open UDP port 902 can expose the VMware environment to unauthorized access if network-level security is weak or default configurations are retained.
- Because UDP is connectionless, it is susceptible to spoofing and reflection attacks, potentially providing an avenue for denial of service (DoS) attacks.
- Improperly segmented management networks may allow malicious actors within the organization to exploit this port to gain control or interfere with VM management.
Common Mitigations:
- Implement strict network segmentation so port 902 is accessible only from trusted management subnets while blocked from user or external networks.
- Use firewall rules to restrict traffic to known management IP addresses.
- Enable role-based access controls within VMware to limit privileges related to console access.
- Monitor network activity for unusual access or traffic patterns to this port as an indication of possible attacks.
- Where supported, encapsulate or secure management communications using SSL/TLS to reduce risks associated with cleartext data transfer, even if encryption is not default on UDP 902.
Related Ports
the 8 most looked-up other ports in remote access — 110 ports carry that label.
| port | service | risk | |||
|---|---|---|---|---|---|
| :8000 | Intel Remote Desktop / Alternate HTTP Port | TCP | Web Services | safe | 84.3k |
| :8888 | D2GS Admin Console | TCP | Remote Access | caution | 83.7k |
| :8881 | Atlasz Secure Server | TCP | Web Services | caution | 67.6k |
| :5938 | TeamViewer | TCPUDP | Remote Access | caution | 65.0k |
| :8291 | Winbox MikroTik Admin | TCP | Security | caution | 62.9k |
| :8008 | IBM HTTP Server Admin | TCP | Web Services | caution | 58.3k |
| :135 | Microsoft EPMAP | TCPUDP | Security | caution | 51.9k |
| :23 | Telnet | TCP | Remote Access | caution | 34.8k |
risk mix of the 8 listed
- safe13%
- caution88%
0 of 8 encrypted