Port 10000: Webmin web administration and Network Data Management Protocol
IANA registers 10000 as ndmp, the Network Data Management Protocol, which the NDMP draft describes as controlling backup, recovery and other transfers of data between primary and secondary storage. The port is also the default for Webmin, which is reached at https://server:10000 after installation.
Port Details
Security Exposure
Webmin's security page states that version 1.890 was released with a backdoor that could allow anyone with knowledge of it to execute commands as root. NVD describes CVE-2019-15107 as a command injection in password_change.cgi in Webmin 1.920 and earlier, and CISA added it to the Known Exploited Vulnerabilities catalog in March 2022. NDMP carries backup and recovery traffic, so it belongs on backup networks.
Hardening
- +Restrict Webmin on 10000 to administrator addresses with the host firewall.
- +Keep Webmin on a current release and apply its security updates promptly.
- +Use strong, unique passwords for Webmin accounts and remove accounts that are no longer needed.
- +Limit NDMP on 10000 to dedicated backup networks and the backup server.
Monitoring
Review Webmin login logs for failures and new sessions from unknown addresses, and alert on 10000 exposure detected by external scans.
Webmin / NDMP Vulnerabilities
1 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2019-15107 | Webmin Command Injection Vulnerability | - | 9.8 | 99.7% | KEV | 2019-08-16 |
Tools for Auditing and Monitoring Webmin / NDMP
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Nuclei
Free / CommercialFast vulnerability scanner powered by community YAML templates to scan web applications, networks, and cloud targets for known defects.
OPENVAS
Free / CommercialFull-featured vulnerability scanner for identifying security flaws, missing patches, and weak configs across network hosts.
Related Tool Categories
Frequently Asked Questions
What is port 10000 used for?→
It is registered to NDMP for backup traffic, and it is the default port for the Webmin administration interface.
Is port 10000 dangerous to expose?→
Exposing Webmin is risky. CVE-2019-15107, a command injection in Webmin 1.920 and earlier, is listed in CISA's Known Exploited Vulnerabilities catalog.
Is port 10000 TCP or UDP?→
IANA registers NDMP on both TCP and UDP 10000. Webmin is a web interface served over HTTPS, which uses TCP.
Which vulnerabilities affect the service on port 10000?→
This database lists 1 CVE related to Webmin / NDMP, 1 of them confirmed as exploited by CISA. Examples: CVE-2019-15107.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 10000 is not guaranteed to be Webmin / NDMP. Exploited-in-the-wild data from the CISA KEV catalog (CC0).