Port 902: VMware vCenter to ESXi management and console traffic
IANA assigns 902 to ideafarm-door, but in practice the port is used by VMware vSphere. Broadcom documents TCP and UDP 902 for core management communication between vCenter Server and ESXi hosts, virtual machine console access from the vSphere Client, and host-to-host migration and provisioning traffic.
Port Details
Security Exposure
Port 902 leads to the hypervisor management plane, so a compromise affects the host and the virtual machines it runs. CISA and FBI advise ESXi operators to update servers, disable the SLP service and ensure the ESXi hypervisor is not configured to be exposed to the public internet. Broadcom documents 902 as a port used between vCenter Server, ESXi hosts and the vSphere Client.
Hardening
- +Keep ESXi and vCenter management ports, including 902, on an isolated management network.
- +Never expose ESXi hosts to the public internet, following CISA and FBI ESXiArgs guidance.
- +Apply current ESXi and vCenter updates; ESXi releases are cumulative.
- +Disable the SLP service on ESXi hosts where it is not required.
Monitoring
Alert on connections to 902 from addresses outside the vCenter and admin jump-host ranges. Forward ESXi host logs to a central collector and review console and login activity.
VMware ESXi (vpxd) Vulnerabilities
4 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2025-22226 | VMware ESXi, Workstation, and Fusion Information Disclosure Vulnerability | - | 7.1 | 1.8% | KEV | 2025-03-04 |
| CVE-2025-22224 | VMware ESXi and Workstation TOCTOU Race Condition Vulnerability | VMware | 9.3 | 1.6% | KEV | 2025-03-04 |
| CVE-2025-22225 | VMware ESXi Arbitrary Write Vulnerability | - | 8.2 | 1.0% | KEV | 2025-03-04 |
| CVE-2024-37085 | VMware ESXi Authentication Bypass Vulnerability | - | 6.8 | 26.8% | KEV | 2024-06-25 |
Tools for Auditing and Monitoring VMware ESXi (vpxd)
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Nessus
CommercialTenable vulnerability scanner with the industry’s largest plugin library; time-limited free Essentials license.
Shodan
FreemiumSearch engine for Internet-connected devices that indexes service banners, open ports, and exposed assets across public IP space.
Related Tool Categories
CSPM scanners, container and Kubernetes policy engines, and cloud configuration auditing tools.
Zero trust access, secure web gateways, firewalls, and perimeter enforcement platforms.
Infrastructure scanners, CVE audit engines, container image inspectors, and exposure management platforms.
Frequently Asked Questions
What is port 902 used for?→
In VMware vSphere it carries vCenter to ESXi management traffic (vpxd), virtual machine console connections and migration traffic, on TCP and UDP.
Is port 902 the IANA port for VMware?→
No. IANA lists 902 as ideafarm-door; VMware's use is a vendor convention documented by Broadcom.
Which vulnerabilities affect the service on port 902?→
This database lists 4 CVEs related to VMware ESXi (vpxd), 4 of them confirmed as exploited by CISA. Examples: CVE-2025-22226, CVE-2025-22224, CVE-2025-22225, CVE-2024-37085.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 902 is not guaranteed to be VMware ESXi (vpxd). Exploited-in-the-wild data from the CISA KEV catalog (CC0).