Port 161: Simple Network Management Protocol
UDP port 161 is the SNMP agent port. RFC 3417 suggests that SNMP command responders listen on UDP 161, where management stations poll network devices and hosts for status and configuration data. Windows includes an SNMP Service that listens on UDP 161.
Port Details
Security Exposure
SNMPv1 and SNMPv2c protect access with community strings that travel in cleartext, so a sniffed or guessed string can give access to a device's management plane (CISA alert TA17-156A). MITRE ATT&CK lists SNMP among services targeted by password guessing. CISA also lists SNMPv2 as a UDP reflection vector, where GetBulk requests give an amplification factor of 6.3.
Hardening
- +Use only SNMPv3 with authPriv (authentication and encryption), as CISA recommends.
- +Limit readable and writable objects with SNMP views that allow-list the needed MIB objects.
- +Apply ACLs so only authorized management stations can query UDP 161.
- +Move SNMP traffic onto a separate, preferably out-of-band, management network.
- +Use different SNMPv3 passwords for authentication and encryption and separate read and write roles.
Monitoring
Log SNMP authentication failures and enable authentication traps, then alert on SNMP queries from addresses outside the management network.
SNMP Vulnerabilities
10 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2025-20352 | Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability | Cisco | 7.7 | 39.4% | KEV | 2025-09-24 |
| CVE-2017-6742 | Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability | Cisco | 8.8 | 21.4% | KEV | 2017-07-17 |
| CVE-2016-6366 | Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability | - | 8.8 | 87.6% | KEV | 2016-08-18 |
| CVE-2017-6736 | Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability | Cisco | 8.8 | 70.4% | KEV | 2017-07-17 |
| CVE-2017-6737 | Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability | Cisco | 8.8 | 45.2% | KEV | 2017-07-17 |
| CVE-2017-6740 | Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability | Cisco | 8.8 | 11.1% | KEV | 2017-07-17 |
| CVE-2017-6743 | Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability | Cisco | 8.8 | 10.9% | KEV | 2017-07-17 |
| CVE-2017-6739 | Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability | IntelliShield | 8.8 | 10.9% | KEV | 2017-07-17 |
| CVE-2017-6738 | Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability | Cisco | 8.8 | 10.9% | KEV | 2017-07-17 |
| CVE-2017-6744 | Cisco IOS Software SNMP Remote Code Execution Vulnerability | Cisco | 8.8 | 7.3% | KEV | 2017-07-17 |
Tools for Auditing and Monitoring SNMP
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Zeek
Open SourceNetwork security monitoring framework that translates raw packet traffic into structured transaction logs and network events.
Suricata
Open SourceHigh-speed network intrusion detection, prevention, and security monitoring engine with deep protocol parsing capabilities.
Related Tool Categories
Frequently Asked Questions
Is SNMP TCP or UDP?→
SNMP normally runs over UDP. CISA notes that all SNMP versions run over UDP, and RFC 3417 maps agents to UDP 161 and notification receivers to UDP 162.
Which SNMP version should be used?→
CISA recommends using only SNMPv3, configured for authPriv where the device supports it, because SNMPv1 and v2c community strings can be sniffed from network traffic.
Should port 161 be open to the internet?→
No. CISA advises restricting SNMP with ACLs to authorized management hosts and segregating it onto a management network.
Which vulnerabilities affect the service on port 161?→
This database lists 10 CVEs related to SNMP, 10 of them confirmed as exploited by CISA. Examples: CVE-2025-20352, CVE-2017-6742, CVE-2016-6366, CVE-2017-6736.
Sources
- IANA Service Name and Transport Protocol Port Number Registry (port 161)
- RFC 3417: Transport Mappings for the Simple Network Management Protocol (SNMP)
- CISA Alert TA17-156A: Reducing the Risk of SNMP Abuse
- CISA Alert TA14-017A: UDP-Based Amplification Attacks
- Microsoft Learn: Service overview and network port requirements for Windows
- MITRE ATT&CK T1110.001: Brute Force, Password Guessing
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 161 is not guaranteed to be SNMP. Exploited-in-the-wild data from the CISA KEV catalog (CC0).