Port 162: SNMP notifications (traps and informs)
UDP port 162 receives SNMP notifications such as traps. RFC 3417 suggests that notification receivers listen on UDP 162, so the port is open on network management stations rather than on the managed devices. The Windows SNMP Trap service receives these messages and passes them to management software.
Port Details
Security Exposure
SNMPv1 and SNMPv2c notifications carry community strings in cleartext, which CISA alert TA17-156A identifies as open to sniffing and replay. MITRE ATT&CK lists SNMP on 162/TCP and UDP among services targeted by password guessing.
Hardening
- +Accept traps only from known device addresses through host or network ACLs.
- +Use SNMPv3 notifications with authentication and encryption.
- +Keep trap receivers on the management network, away from internet-facing interfaces.
- +Separate trap reception from accounts that have SNMP write access, as CISA advises.
Monitoring
Alert on traps from unknown sources and on sudden spikes in trap volume. Authentication-failure traps from devices show that an unrecognized system tried to query them.
SNMP trap Vulnerabilities
10 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2025-20352 | Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability | Cisco | 7.7 | 39.4% | KEV | 2025-09-24 |
| CVE-2017-6742 | Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability | Cisco | 8.8 | 21.4% | KEV | 2017-07-17 |
| CVE-2016-6366 | Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability | - | 8.8 | 87.6% | KEV | 2016-08-18 |
| CVE-2017-6736 | Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability | Cisco | 8.8 | 70.4% | KEV | 2017-07-17 |
| CVE-2017-6737 | Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability | Cisco | 8.8 | 45.2% | KEV | 2017-07-17 |
| CVE-2017-6740 | Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability | Cisco | 8.8 | 11.1% | KEV | 2017-07-17 |
| CVE-2017-6743 | Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability | Cisco | 8.8 | 10.9% | KEV | 2017-07-17 |
| CVE-2017-6739 | Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability | IntelliShield | 8.8 | 10.9% | KEV | 2017-07-17 |
| CVE-2017-6738 | Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability | Cisco | 8.8 | 10.9% | KEV | 2017-07-17 |
| CVE-2017-6744 | Cisco IOS Software SNMP Remote Code Execution Vulnerability | Cisco | 8.8 | 7.3% | KEV | 2017-07-17 |
Tools for Auditing and Monitoring SNMP trap
Zeek
Open SourceNetwork security monitoring framework that translates raw packet traffic into structured transaction logs and network events.
Wireshark
Open SourceNetwork packet analyzer and protocol inspection tool for capturing live traffic and debugging network communications in detail.
Suricata
Open SourceHigh-speed network intrusion detection, prevention, and security monitoring engine with deep protocol parsing capabilities.
Related Tool Categories
Frequently Asked Questions
What is the difference between port 161 and port 162?→
Agents listen on UDP 161 for requests from managers. Managers listen on UDP 162 for traps and other notifications sent by agents (RFC 3417).
Does every device need port 162 open?→
No. Only systems that receive notifications, such as network management stations, need to listen on UDP 162.
Which vulnerabilities affect the service on port 162?→
This database lists 10 CVEs related to SNMP trap, 10 of them confirmed as exploited by CISA. Examples: CVE-2025-20352, CVE-2017-6742, CVE-2016-6366, CVE-2017-6736.
Sources
- IANA Service Name and Transport Protocol Port Number Registry (port 162)
- RFC 3417: Transport Mappings for the Simple Network Management Protocol (SNMP)
- CISA Alert TA17-156A: Reducing the Risk of SNMP Abuse
- Microsoft Learn: Service overview and network port requirements for Windows
- MITRE ATT&CK T1110.001: Brute Force, Password Guessing
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 162 is not guaranteed to be SNMP trap. Exploited-in-the-wild data from the CISA KEV catalog (CC0).