Port 5900: Virtual Network Computing (Remote Framebuffer protocol)
Port 5900 is where VNC servers accept Remote Framebuffer (RFB) connections for remote desktop control. RFC 6143 states that an RFB client contacts the server on TCP 5900 and that server N typically listens on 5900+N. IANA registers rfb on TCP and UDP 5900.
Port Details
Security Exposure
RFC 6143 states that RFB offers only an optional, cryptographically weak password check and no protection against observation or tampering. Shadowserver rates accessible VNC as high severity and began tagging instances with no authentication in 2025. MITRE ATT&CK T1021.005 documents adversaries using valid accounts to control machines over VNC.
Hardening
- +Keep 5900 to 5905 off the internet and reach VNC through a VPN or SSH tunnel.
- +Require authentication and pick a VNC server that supports encrypted security types.
- +Bind VNC to localhost when it is only used over a tunnel.
- +Remove VNC servers that are not in use and keep the rest patched.
Monitoring
Alert on any listener on TCP 5900 to 5905 that is not in the inventory, and log connection attempts and authentication failures from the VNC server.
Tools for Auditing and Monitoring VNC
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Shodan
FreemiumSearch engine for Internet-connected devices that indexes service banners, open ports, and exposed assets across public IP space.
OPENVAS
Free / CommercialFull-featured vulnerability scanner for identifying security flaws, missing patches, and weak configs across network hosts.
Related Tool Categories
Packet capture tools, protocol analyzers, and network security monitors for traffic visibility.
Zero trust access, secure web gateways, firewalls, and perimeter enforcement platforms.
Infrastructure scanners, CVE audit engines, container image inspectors, and exposure management platforms.
Frequently Asked Questions
Is VNC on port 5900 encrypted?→
Not by the base protocol. RFC 6143 says RFB provides no protection against observation of the data stream and suggests encrypted security types, IPsec or SSH.
Why does VNC use 5901 and 5902?→
RFC 6143 says server N typically listens on 5900+N, so additional displays use 5901, 5902 and so on.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 5900 is not guaranteed to be VNC. Exploited-in-the-wild data from the CISA KEV catalog (CC0).