Skip to main content

Port Details

Port
161
Transport
UDP
Service
SNMP
IANA service name
snmp
Range
System port (0-1023)
Related ports

Security Exposure

SNMPv1 and SNMPv2c protect access with community strings that travel in cleartext, so a sniffed or guessed string can give access to a device's management plane (CISA alert TA17-156A). MITRE ATT&CK lists SNMP among services targeted by password guessing. CISA also lists SNMPv2 as a UDP reflection vector, where GetBulk requests give an amplification factor of 6.3.

Hardening

  • +Use only SNMPv3 with authPriv (authentication and encryption), as CISA recommends.
  • +Limit readable and writable objects with SNMP views that allow-list the needed MIB objects.
  • +Apply ACLs so only authorized management stations can query UDP 161.
  • +Move SNMP traffic onto a separate, preferably out-of-band, management network.
  • +Use different SNMPv3 passwords for authentication and encryption and separate read and write roles.

Monitoring

Log SNMP authentication failures and enable authentication traps, then alert on SNMP queries from addresses outside the management network.

SNMP Vulnerabilities

10 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2025-20352
Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability
Cisco7.739.4%KEV2025-09-24
CVE-2017-6742
Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
Cisco8.821.4%KEV2017-07-17
CVE-2016-6366
Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability
-8.887.6%KEV2016-08-18
CVE-2017-6736
Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
Cisco8.870.4%KEV2017-07-17
CVE-2017-6737
Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
Cisco8.845.2%KEV2017-07-17
CVE-2017-6740
Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
Cisco8.811.1%KEV2017-07-17
CVE-2017-6743
Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
Cisco8.810.9%KEV2017-07-17
CVE-2017-6739
Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
IntelliShield8.810.9%KEV2017-07-17
CVE-2017-6738
Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
Cisco8.810.9%KEV2017-07-17
CVE-2017-6744
Cisco IOS Software SNMP Remote Code Execution Vulnerability
Cisco8.87.3%KEV2017-07-17

Tools for Auditing and Monitoring SNMP

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Zeek

Open Source
Network Monitoring Tools

Network security monitoring framework that translates raw packet traffic into structured transaction logs and network events.

LicenseBSD-3-Clause
PlatformLinux, FreeBSD, macOS, OpenBSD

Suricata

Open Source
Network Monitoring Tools

High-speed network intrusion detection, prevention, and security monitoring engine with deep protocol parsing capabilities.

LicenseGPL-2.0-only
PlatformLinux, FreeBSD, macOS, Windows

Frequently Asked Questions

Is SNMP TCP or UDP?→

SNMP normally runs over UDP. CISA notes that all SNMP versions run over UDP, and RFC 3417 maps agents to UDP 161 and notification receivers to UDP 162.

Which SNMP version should be used?→

CISA recommends using only SNMPv3, configured for authPriv where the device supports it, because SNMPv1 and v2c community strings can be sniffed from network traffic.

Should port 161 be open to the internet?→

No. CISA advises restricting SNMP with ACLs to authorized management hosts and segregating it onto a management network.

Which vulnerabilities affect the service on port 161?→

This database lists 10 CVEs related to SNMP, 10 of them confirmed as exploited by CISA. Examples: CVE-2025-20352, CVE-2017-6742, CVE-2016-6366, CVE-2017-6736.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 161 is not guaranteed to be SNMP. Exploited-in-the-wild data from the CISA KEV catalog (CC0).