Skip to main content

Port Details

Port
631
Transport
TCP / UDP
Service
IPP
IANA service name
ipp, ipps (tcp)
Range
System port (0-1023)

Security Exposure

cups-browsed versions up to 2.0.1 bound to UDP 631 on all interfaces and trusted packets from any source (CVE-2024-47176). Chained with related flaws, this allowed a remote attacker to add a malicious printer and run commands when a print job started. Rapid7, citing the researcher, reported that systems were exploitable from the internet or across segments when UDP 631 was exposed, and its own testing found that blocking UDP 631 does not stop exploitation on the LAN.

Hardening

  • +Stop and disable cups-browsed where network printer discovery is not needed.
  • +Apply vendor or distribution updates for cups-browsed, libcupsfilters, libppd and cups-filters.
  • +Block UDP 631 at the network edge and between segments, noting that this does not prevent exploitation on the LAN.
  • +Use ipps (IPP over HTTPS) for print traffic that crosses networks.

Monitoring

Flag hosts listening on UDP 631 and unexpected new printer queues on Linux systems. Watch for outbound IPP connections from servers to internet addresses.

Tools for Auditing and Monitoring IPP

osquery

Open Source
SIEM Tools

Operating system instrumentation framework that exposes low-level system telemetry as SQL tables for security monitoring.

LicenseApache-2.0 OR GPL-2.0-only
PlatformLinux, macOS, Windows

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Nessus

Commercial
Vulnerability Scanning

Tenable vulnerability scanner with the industry’s largest plugin library; time-limited free Essentials license.

LicenseProprietary
PlatformLinux, Windows, Web

Frequently Asked Questions

Is port 631 TCP or UDP?→

IPP uses TCP 631. cups-browsed used UDP 631 for legacy CUPS browsing, which was the entry point for CVE-2024-47176.

How do I mitigate the CUPS cups-browsed vulnerability?→

The OpenPrinting advisory recommends stopping or disabling cups-browsed, or turning off legacy CUPS browsing. Rapid7 advises applying vendor patches once available and also lists blocking UDP 631, which does not prevent exploitation on the LAN.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 631 is not guaranteed to be IPP. Exploited-in-the-wild data from the CISA KEV catalog (CC0).