Port 631: Internet Printing Protocol
TCP 631 is the IANA well-known port for the Internet Printing Protocol, which carries print jobs over HTTP. RFC 3510 requires ipp URLs without an explicit port to resolve to 631, and RFC 7472 defines IPP over HTTPS (ipps). CUPS, an IPP-based printing system mainly for Linux and UNIX-like systems, serves its HTTP-based web administration on TCP 631, and its cups-browsed service listens on UDP 631.
Port Details
Security Exposure
cups-browsed versions up to 2.0.1 bound to UDP 631 on all interfaces and trusted packets from any source (CVE-2024-47176). Chained with related flaws, this allowed a remote attacker to add a malicious printer and run commands when a print job started. Rapid7, citing the researcher, reported that systems were exploitable from the internet or across segments when UDP 631 was exposed, and its own testing found that blocking UDP 631 does not stop exploitation on the LAN.
Hardening
- +Stop and disable cups-browsed where network printer discovery is not needed.
- +Apply vendor or distribution updates for cups-browsed, libcupsfilters, libppd and cups-filters.
- +Block UDP 631 at the network edge and between segments, noting that this does not prevent exploitation on the LAN.
- +Use ipps (IPP over HTTPS) for print traffic that crosses networks.
Monitoring
Flag hosts listening on UDP 631 and unexpected new printer queues on Linux systems. Watch for outbound IPP connections from servers to internet addresses.
Tools for Auditing and Monitoring IPP
osquery
Open SourceOperating system instrumentation framework that exposes low-level system telemetry as SQL tables for security monitoring.
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Nessus
CommercialTenable vulnerability scanner with the industry’s largest plugin library; time-limited free Essentials license.
Related Tool Categories
Frequently Asked Questions
Is port 631 TCP or UDP?→
IPP uses TCP 631. cups-browsed used UDP 631 for legacy CUPS browsing, which was the entry point for CVE-2024-47176.
How do I mitigate the CUPS cups-browsed vulnerability?→
The OpenPrinting advisory recommends stopping or disabling cups-browsed, or turning off legacy CUPS browsing. Rapid7 advises applying vendor patches once available and also lists blocking UDP 631, which does not prevent exploitation on the LAN.
Sources
- IANA Service Name and Port Number Registry: port 631
- RFC 3510: Internet Printing Protocol/1.1: IPP URL Scheme
- RFC 7472: IPP over HTTPS Transport Binding and the 'ipps' URI Scheme
- OpenPrinting cups-browsed security advisory GHSA-rj88-6mr5-rcw8
- Rapid7: Multiple vulnerabilities in Common Unix Printing System (CUPS)
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 631 is not guaranteed to be IPP. Exploited-in-the-wild data from the CISA KEV catalog (CC0).