Skip to main content

Port Details

Port
9100
Transport
TCP
Service
Raw printing / node_exporter
IANA service name
hp-pdl-datastr, pdl-datastream
Range
User port (1024-49151)
Related ports

Security Exposure

NVD's entry for CVE-2024-51982 describes an unauthenticated attacker who connects to TCP 9100 and issues a Printer Job Language (PJL) command that crashes the device repeatedly. On servers, node_exporter publishes hardware and OS metrics over HTTP on 9100 to anyone who can reach it unless TLS and access controls are configured.

Hardening

  • +Allow 9100 on printers only from print servers, and route user printing through those servers.
  • +Block 9100 at the perimeter so printers are never reachable from the internet.
  • +Apply printer firmware updates for PJL and raw-printing vulnerabilities.
  • +Restrict node_exporter to the Prometheus server and enable TLS through its web configuration file.

Monitoring

Alert on 9100 connections to printers from hosts other than the print servers, and on any 9100 traffic crossing the perimeter.

Tools for Auditing and Monitoring Raw printing / node_exporter

runZero

Freemium
Vulnerability Scanning

Asset inventory and exposure management platform with agentless discovery across IT, OT, and cloud.

LicenseProprietary
PlatformWeb

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Zeek

Open Source
Network Monitoring Tools

Network security monitoring framework that translates raw packet traffic into structured transaction logs and network events.

LicenseBSD-3-Clause
PlatformLinux, FreeBSD, macOS, OpenBSD

Frequently Asked Questions

What is port 9100 used for?→

It is the usual port for AppSocket (JetDirect) raw printing. The Prometheus node_exporter also uses 9100 by default.

Is port 9100 a security risk?→

On printers, it can be if it is reachable from untrusted networks. NVD describes CVE-2024-51982 as triggerable by an unauthenticated attacker who can connect to TCP 9100.

Is port 9100 TCP or UDP?→

Raw printing and node_exporter both use TCP. IANA lists both transports for the registered names.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 9100 is not guaranteed to be Raw printing / node_exporter. Exploited-in-the-wild data from the CISA KEV catalog (CC0).