Port 902VMware vSphere Management

Port 902 is primarily used by VMware vSphere for communication between the vSphere Client, ESXi hosts, and VMware management agents. It facilitates remote management, tasks automation, and host operations. The port enables secure communication pathways for remote console access, management functionalities, data transfers within VMware infrastructures, and integration with vCenter Server for centralized management..

transport
tcp

single transport

in transit
cleartext

payload readable on path

assignment
unofficial

used by convention

risk
4/10

caution

lookups
28,697

rank 41 of 993 · top 4%

3 other services are registered on port 902. compare all 4

Technical Details

what runs on :902

Overview:

VMware vSphere utilizes port 902 to establish connections between the vSphere Client or vCenter Server and ESXi hosts. It plays a critical role in VMware's host management and remote console operations. When a user opens a console to a VM through vSphere Client or Web Client, communication typically flows through port 902.

Data Exchange:

This port is used by VMware's hostd and vpxa management agents to facilitate operations such as VM power controls, migrations, backups, and host monitoring. Backup solutions, third-party management tools, and VMware services rely heavily on port 902 to interact with ESXi hosts effectively.

Protocol and Service Context:

Port 902 primarily uses TCP (and UDP for some legacy heartbeat communication, though less commonly now). It does not utilize SCTP. Traffic traversing this port is largely unencrypted unless additional security layers (like SSL) are configured. The port is essential for the internal communication within VMware deployments but is less frequently exposed beyond trusted internal management networks.

Security Information

exposure of :902

risk score

4/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

remote access averages 4.0 across 110 ports — this one sits level with it.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

unofficial

used by convention, not registered — what answers here varies by deployment

reachable over

tcp

every listening transport is another surface to filter at the edge

security overview

Common Vulnerabilities:

  • Unauthorized access if the port is left open to untrusted networks, enabling attackers to gain remote management capabilities.
  • Man-in-the-middle attacks due to unencrypted communications, potentially exposing sensitive management traffic.
  • Exploitation via malware or compromised administrative systems that can abuse open management interfaces.

Mitigations:

  • Restrict port 902 access to trusted management networks only, segmenting it away from general user or internet-facing segments.
  • Implement network firewall rules and access controls to limit which systems can communicate over port 902.
  • Enable SSL or other encryption and authentication methods to protect management sessions.
  • Regularly monitor and update VMware infrastructure to reduce vulnerabilities related to known exploits.
  • Employ intrusion detection or behavioral monitoring around VMware management ports.

the 8 most looked-up other ports in remote access — 110 ports carry that label.

risk mix of the 8 listed

  • safe13%
  • caution88%

0 of 8 encrypted