Skip to main content

Port Details

Port
5900
Transport
TCP
Service
VNC
IANA service name
rfb
Range
User port (1024-49151)
Related ports
58005901

Security Exposure

RFC 6143 states that RFB offers only an optional, cryptographically weak password check and no protection against observation or tampering. Shadowserver rates accessible VNC as high severity and began tagging instances with no authentication in 2025. MITRE ATT&CK T1021.005 documents adversaries using valid accounts to control machines over VNC.

Hardening

  • +Keep 5900 to 5905 off the internet and reach VNC through a VPN or SSH tunnel.
  • +Require authentication and pick a VNC server that supports encrypted security types.
  • +Bind VNC to localhost when it is only used over a tunnel.
  • +Remove VNC servers that are not in use and keep the rest patched.

Monitoring

Alert on any listener on TCP 5900 to 5905 that is not in the inventory, and log connection attempts and authentication failures from the VNC server.

Tools for Auditing and Monitoring VNC

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Shodan

Freemium
Open Source Intelligence Tools

Search engine for Internet-connected devices that indexes service banners, open ports, and exposed assets across public IP space.

LicenseProprietary (service); MIT (Python client)
PlatformWeb, Linux, macOS, Windows

OPENVAS

Free / Commercial
Vulnerability Scanning

Full-featured vulnerability scanner for identifying security flaws, missing patches, and weak configs across network hosts.

LicenseGPL-2.0-only (C scanner); GPL-2.0-or-later WITH OpenSSL-exception (Rust)
PlatformLinux

Frequently Asked Questions

Is VNC on port 5900 encrypted?→

Not by the base protocol. RFC 6143 says RFB provides no protection against observation of the data stream and suggests encrypted security types, IPsec or SSH.

Why does VNC use 5901 and 5902?→

RFC 6143 says server N typically listens on 5900+N, so additional displays use 5901, 5902 and so on.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 5900 is not guaranteed to be VNC. Exploited-in-the-wild data from the CISA KEV catalog (CC0).