Skip to main content

Port Details

Port
10000
Transport
TCP
Service
Webmin / NDMP
IANA service name
ndmp
Range
User port (1024-49151)

Security Exposure

Webmin's security page states that version 1.890 was released with a backdoor that could allow anyone with knowledge of it to execute commands as root. NVD describes CVE-2019-15107 as a command injection in password_change.cgi in Webmin 1.920 and earlier, and CISA added it to the Known Exploited Vulnerabilities catalog in March 2022. NDMP carries backup and recovery traffic, so it belongs on backup networks.

Hardening

  • +Restrict Webmin on 10000 to administrator addresses with the host firewall.
  • +Keep Webmin on a current release and apply its security updates promptly.
  • +Use strong, unique passwords for Webmin accounts and remove accounts that are no longer needed.
  • +Limit NDMP on 10000 to dedicated backup networks and the backup server.

Monitoring

Review Webmin login logs for failures and new sessions from unknown addresses, and alert on 10000 exposure detected by external scans.

Webmin / NDMP Vulnerabilities

1 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2019-15107
Webmin Command Injection Vulnerability
-9.899.7%KEV2019-08-16

Tools for Auditing and Monitoring Webmin / NDMP

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Nuclei

Free / Commercial
Vulnerability Scanning

Fast vulnerability scanner powered by community YAML templates to scan web applications, networks, and cloud targets for known defects.

LicenseMIT
PlatformLinux, macOS, Windows

OPENVAS

Free / Commercial
Vulnerability Scanning

Full-featured vulnerability scanner for identifying security flaws, missing patches, and weak configs across network hosts.

LicenseGPL-2.0-only (C scanner); GPL-2.0-or-later WITH OpenSSL-exception (Rust)
PlatformLinux

Frequently Asked Questions

What is port 10000 used for?→

It is registered to NDMP for backup traffic, and it is the default port for the Webmin administration interface.

Is port 10000 dangerous to expose?→

Exposing Webmin is risky. CVE-2019-15107, a command injection in Webmin 1.920 and earlier, is listed in CISA's Known Exploited Vulnerabilities catalog.

Is port 10000 TCP or UDP?→

IANA registers NDMP on both TCP and UDP 10000. Webmin is a web interface served over HTTPS, which uses TCP.

Which vulnerabilities affect the service on port 10000?→

This database lists 1 CVE related to Webmin / NDMP, 1 of them confirmed as exploited by CISA. Examples: CVE-2019-15107.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 10000 is not guaranteed to be Webmin / NDMP. Exploited-in-the-wild data from the CISA KEV catalog (CC0).