Skip to main content

Port Details

Port
990
Transport
TCP
Service
FTPS (implicit)
IANA service name
ftps
Range
System port (0-1023)
Related ports
98921

Security Exposure

FTPS servers accept user logins, so an internet-facing 990 listener draws password guessing. Weak TLS settings or optional encryption of the data channel can still leave file contents readable.

Hardening

  • +Prefer explicit FTPS (AUTH TLS, RFC 4217) for new deployments; implicit FTPS on 990 comes from an expired draft.
  • +Disable TLS 1.0 and 1.1 as RFC 9325 requires, and protect the data channel as well as the control channel (RFC 4217 starts data connections in the Clear state).
  • +Restrict access to known partner IP addresses and lock out repeated failed logins.
  • +Keep the FTP server software patched.

Monitoring

Log logins, failures and file operations on the FTP server and alert on spikes in failures or transfers from new addresses.

FTPS (implicit) Vulnerabilities

3 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2025-47813
Wing FTP Server Information Disclosure Vulnerability
wftpserver4.363.1%KEV2025-07-10
CVE-2025-47812
Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability
wftpserver10.093.2%KEV2025-07-10
CVE-2021-35211
Serv-U Remote Memory Escape Vulnerability
SolarWinds9.091.2%KEV2021-07-14

Tools for Auditing and Monitoring FTPS (implicit)

Hydra

Open Source
Password Cracking

Parallelized network login auditing tool that tests dozens of remote authentication protocols including SSH, SMB, RDP, HTTP, and database services.

LicenseAGPL-3.0-only with OpenSSL exception
PlatformLinux, macOS, Windows, BSD, Solaris

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Nessus

Commercial
Vulnerability Scanning

Tenable vulnerability scanner with the industry’s largest plugin library; time-limited free Essentials license.

LicenseProprietary
PlatformLinux, Windows, Web

Frequently Asked Questions

What is the difference between FTPS on port 990 and port 21?→

Port 990 is the IANA ftps port; with implicit FTPS the TLS session is negotiated as soon as the client connects, before the FTP greeting. RFC 4217 defines explicit FTPS, where the client sends AUTH TLS on the regular FTP control connection.

Which port carries FTPS data connections?→

IANA assigns port 989 (ftps-data) to the FTP data connection over TLS/SSL, paired with 990 for the control connection.

Which vulnerabilities affect the service on port 990?→

This database lists 3 CVEs related to FTPS (implicit), 3 of them confirmed as exploited by CISA. Examples: CVE-2025-47813, CVE-2025-47812, CVE-2021-35211.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 990 is not guaranteed to be FTPS (implicit). Exploited-in-the-wild data from the CISA KEV catalog (CC0).