Port 1900: Simple Service Discovery Protocol (UPnP discovery)
SSDP is the discovery layer of UPnP. Devices and control points exchange search and advertisement messages on UDP 1900, using the multicast address 239.255.255.250:1900, according to the UPnP Device Architecture.
Port Details
Security Exposure
SSDP is meant for local discovery, but devices that answer SSDP search requests from the internet can be abused as reflectors. CISA's alert on UDP-based amplification lists SSDP with an amplification factor of about 30.8 for a SEARCH request. Shadowserver reports internet-accessible SSDP hosts as high severity because of this abuse potential.
Hardening
- +Block inbound UDP 1900 from the internet at the perimeter and on internet-facing hosts.
- +Disable UPnP and SSDP on routers and devices that do not need automatic discovery.
- +Keep SSDP confined to the local segment and do not forward it across WAN interfaces.
- +Apply firmware updates for routers and embedded devices that implement SSDP.
Monitoring
Monitor flow data for large volumes of outbound UDP traffic sourced from port 1900, which indicates reflection. CISA also recommends watching for unusual request counts to at-risk UDP services.
SSDP Vulnerabilities
2 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2019-1405 | Microsoft Windows Universal Plug and Play (UPnP) Service Privilege Escalation Vulnerability | Microsoft | 7.8 | 30.2% | KEV | 2019-11-12 |
| CVE-2026-3485 | D-Link DIR-868L SSDP Service sub_1BF84 os command injection | D-Link | 10.0 | 6.7% | 2026-03-03 |
Tools for Auditing and Monitoring SSDP
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Zeek
Open SourceNetwork security monitoring framework that translates raw packet traffic into structured transaction logs and network events.
Suricata
Open SourceHigh-speed network intrusion detection, prevention, and security monitoring engine with deep protocol parsing capabilities.
Related Tool Categories
Frequently Asked Questions
What is port 1900 used for?→
UDP 1900 carries SSDP, the discovery protocol of UPnP. Devices use it to announce themselves and answer searches on the local network.
Should port 1900 be open to the internet?→
No. SSDP is a local discovery protocol, and CISA and Shadowserver document its abuse for reflected denial of service attacks when it is reachable from the internet.
Is SSDP TCP or UDP?→
SSDP discovery uses UDP, including multicast to 239.255.255.250 on port 1900. IANA lists both transports for the registration.
Which vulnerabilities affect the service on port 1900?→
This database lists 2 CVEs related to SSDP, 1 of them confirmed as exploited by CISA. Examples: CVE-2019-1405, CVE-2026-3485.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 1900 is not guaranteed to be SSDP. Exploited-in-the-wild data from the CISA KEV catalog (CC0).