Skip to main content

Port Details

Port
20
Transport
TCP
Service
FTP data
IANA service name
ftp-data
Range
System port (0-1023)
Related ports

Security Exposure

FTP data connections carry file contents unencrypted, so anyone on the network path can read or alter transferred files. RFC 2577 describes the FTP bounce attack, where a client uses the PORT command to make the server open data connections to third-party hosts and services. Port 20 only exists alongside an FTP control service on port 21, so its exposure follows the risks of that service.

Hardening

  • +Replace FTP with SFTP or FTPS, as UK Government Cyber Unit guidance recommends.
  • +Configure the server to refuse PORT commands that point to ports below 1024, as RFC 2577 suggests against bounce attacks.
  • +Consider disabling the PORT command and allowing passive mode only, which RFC 2577 lists as a bounce attack defense.
  • +Remove inbound firewall and port forwarding rules for FTP ports when the service is not needed.

Monitoring

Log FTP data connections together with the control session on port 21. Outbound data connections to hosts other than the client that opened the control session can indicate PORT command abuse.

FTP data Vulnerabilities

4 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2015-3306
ProFTPD Improper Access Control Vulnerability
-10.096.8%KEV2015-05-18
CVE-2025-47813
Wing FTP Server Information Disclosure Vulnerability
wftpserver4.363.1%KEV2025-07-10
CVE-2025-47812
Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability
wftpserver10.093.2%KEV2025-07-10
CVE-2021-35211
Serv-U Remote Memory Escape Vulnerability
SolarWinds9.091.2%KEV2021-07-14

Tools for Auditing and Monitoring FTP data

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Zeek

Open Source
Network Monitoring Tools

Network security monitoring framework that translates raw packet traffic into structured transaction logs and network events.

LicenseBSD-3-Clause
PlatformLinux, FreeBSD, macOS, OpenBSD

Wireshark

Open Source
Network Monitoring Tools

Network packet analyzer and protocol inspection tool for capturing live traffic and debugging network communications in detail.

LicenseGPL-2.0-or-later
PlatformWindows, macOS, Linux, BSD

Frequently Asked Questions

Is port 20 TCP or UDP?→

FTP runs over TCP, so port 20 data connections are TCP connections. IANA also lists UDP and SCTP entries for ftp-data, but they are not used by standard FTP.

What is the difference between port 20 and port 21?→

Port 21 carries the FTP control connection for commands and replies. Port 20 is the server's data port in active mode; in passive mode the server uses a dynamic high port for data.

Does FTP always use port 20?→

No. Port 20 is used only in active mode. In passive mode, requested with the PASV command, the client opens the data connection to a port the server chooses.

Which vulnerabilities affect the service on port 20?→

This database lists 4 CVEs related to FTP data, 4 of them confirmed as exploited by CISA. Examples: CVE-2015-3306, CVE-2025-47813, CVE-2025-47812, CVE-2021-35211.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 20 is not guaranteed to be FTP data. Exploited-in-the-wild data from the CISA KEV catalog (CC0).