Skip to main content

Port Details

Port
1900
Transport
UDP
Service
SSDP
IANA service name
ssdp
Range
User port (1024-49151)

Security Exposure

SSDP is meant for local discovery, but devices that answer SSDP search requests from the internet can be abused as reflectors. CISA's alert on UDP-based amplification lists SSDP with an amplification factor of about 30.8 for a SEARCH request. Shadowserver reports internet-accessible SSDP hosts as high severity because of this abuse potential.

Hardening

  • +Block inbound UDP 1900 from the internet at the perimeter and on internet-facing hosts.
  • +Disable UPnP and SSDP on routers and devices that do not need automatic discovery.
  • +Keep SSDP confined to the local segment and do not forward it across WAN interfaces.
  • +Apply firmware updates for routers and embedded devices that implement SSDP.

Monitoring

Monitor flow data for large volumes of outbound UDP traffic sourced from port 1900, which indicates reflection. CISA also recommends watching for unusual request counts to at-risk UDP services.

SSDP Vulnerabilities

2 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2019-1405
Microsoft Windows Universal Plug and Play (UPnP) Service Privilege Escalation Vulnerability
Microsoft7.830.2%KEV2019-11-12
CVE-2026-3485
D-Link DIR-868L SSDP Service sub_1BF84 os command injection
D-Link10.06.7%2026-03-03

Tools for Auditing and Monitoring SSDP

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Zeek

Open Source
Network Monitoring Tools

Network security monitoring framework that translates raw packet traffic into structured transaction logs and network events.

LicenseBSD-3-Clause
PlatformLinux, FreeBSD, macOS, OpenBSD

Suricata

Open Source
Network Monitoring Tools

High-speed network intrusion detection, prevention, and security monitoring engine with deep protocol parsing capabilities.

LicenseGPL-2.0-only
PlatformLinux, FreeBSD, macOS, Windows

Frequently Asked Questions

What is port 1900 used for?→

UDP 1900 carries SSDP, the discovery protocol of UPnP. Devices use it to announce themselves and answer searches on the local network.

Should port 1900 be open to the internet?→

No. SSDP is a local discovery protocol, and CISA and Shadowserver document its abuse for reflected denial of service attacks when it is reachable from the internet.

Is SSDP TCP or UDP?→

SSDP discovery uses UDP, including multicast to 239.255.255.250 on port 1900. IANA lists both transports for the registration.

Which vulnerabilities affect the service on port 1900?→

This database lists 2 CVEs related to SSDP, 1 of them confirmed as exploited by CISA. Examples: CVE-2019-1405, CVE-2026-3485.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 1900 is not guaranteed to be SSDP. Exploited-in-the-wild data from the CISA KEV catalog (CC0).