Port 20: File Transfer Protocol data channel (active mode)
Port 20 is the default data port of an FTP server. RFC 959 places it next to the control port (L-1), and in active mode the server opens data connections from port 20 back to the client. Passive mode transfers use a dynamically assigned high port instead.
Port Details
Security Exposure
FTP data connections carry file contents unencrypted, so anyone on the network path can read or alter transferred files. RFC 2577 describes the FTP bounce attack, where a client uses the PORT command to make the server open data connections to third-party hosts and services. Port 20 only exists alongside an FTP control service on port 21, so its exposure follows the risks of that service.
Hardening
- +Replace FTP with SFTP or FTPS, as UK Government Cyber Unit guidance recommends.
- +Configure the server to refuse PORT commands that point to ports below 1024, as RFC 2577 suggests against bounce attacks.
- +Consider disabling the PORT command and allowing passive mode only, which RFC 2577 lists as a bounce attack defense.
- +Remove inbound firewall and port forwarding rules for FTP ports when the service is not needed.
Monitoring
Log FTP data connections together with the control session on port 21. Outbound data connections to hosts other than the client that opened the control session can indicate PORT command abuse.
FTP data Vulnerabilities
4 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2015-3306 | ProFTPD Improper Access Control Vulnerability | - | 10.0 | 96.8% | KEV | 2015-05-18 |
| CVE-2025-47813 | Wing FTP Server Information Disclosure Vulnerability | wftpserver | 4.3 | 63.1% | KEV | 2025-07-10 |
| CVE-2025-47812 | Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability | wftpserver | 10.0 | 93.2% | KEV | 2025-07-10 |
| CVE-2021-35211 | Serv-U Remote Memory Escape Vulnerability | SolarWinds | 9.0 | 91.2% | KEV | 2021-07-14 |
Tools for Auditing and Monitoring FTP data
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Zeek
Open SourceNetwork security monitoring framework that translates raw packet traffic into structured transaction logs and network events.
Wireshark
Open SourceNetwork packet analyzer and protocol inspection tool for capturing live traffic and debugging network communications in detail.
Related Tool Categories
Frequently Asked Questions
Is port 20 TCP or UDP?→
FTP runs over TCP, so port 20 data connections are TCP connections. IANA also lists UDP and SCTP entries for ftp-data, but they are not used by standard FTP.
What is the difference between port 20 and port 21?→
Port 21 carries the FTP control connection for commands and replies. Port 20 is the server's data port in active mode; in passive mode the server uses a dynamic high port for data.
Does FTP always use port 20?→
No. Port 20 is used only in active mode. In passive mode, requested with the PASV command, the client opens the data connection to a port the server chooses.
Which vulnerabilities affect the service on port 20?→
This database lists 4 CVEs related to FTP data, 4 of them confirmed as exploited by CISA. Examples: CVE-2015-3306, CVE-2025-47813, CVE-2025-47812, CVE-2021-35211.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 20 is not guaranteed to be FTP data. Exploited-in-the-wild data from the CISA KEV catalog (CC0).