Port 990: FTP control channel over implicit TLS
IANA assigns TCP 990 to the FTP control connection over TLS/SSL (ftps) and 989 to the matching data connection. With implicit FTPS, the client connects to port 990 and the server delays its welcome greeting until the TLS session is negotiated; Microsoft's [MS-FTPS] notes this mode was originally documented in a draft that has expired. RFC 4217 standardizes the explicit alternative, where the client issues AUTH TLS on the regular FTP control connection (port 21).
Port Details
Security Exposure
FTPS servers accept user logins, so an internet-facing 990 listener draws password guessing. Weak TLS settings or optional encryption of the data channel can still leave file contents readable.
Hardening
- +Prefer explicit FTPS (AUTH TLS, RFC 4217) for new deployments; implicit FTPS on 990 comes from an expired draft.
- +Disable TLS 1.0 and 1.1 as RFC 9325 requires, and protect the data channel as well as the control channel (RFC 4217 starts data connections in the Clear state).
- +Restrict access to known partner IP addresses and lock out repeated failed logins.
- +Keep the FTP server software patched.
Monitoring
Log logins, failures and file operations on the FTP server and alert on spikes in failures or transfers from new addresses.
FTPS (implicit) Vulnerabilities
3 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2025-47813 | Wing FTP Server Information Disclosure Vulnerability | wftpserver | 4.3 | 63.1% | KEV | 2025-07-10 |
| CVE-2025-47812 | Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability | wftpserver | 10.0 | 93.2% | KEV | 2025-07-10 |
| CVE-2021-35211 | Serv-U Remote Memory Escape Vulnerability | SolarWinds | 9.0 | 91.2% | KEV | 2021-07-14 |
Tools for Auditing and Monitoring FTPS (implicit)
Hydra
Open SourceParallelized network login auditing tool that tests dozens of remote authentication protocols including SSH, SMB, RDP, HTTP, and database services.
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Nessus
CommercialTenable vulnerability scanner with the industry’s largest plugin library; time-limited free Essentials license.
Related Tool Categories
Frequently Asked Questions
What is the difference between FTPS on port 990 and port 21?→
Port 990 is the IANA ftps port; with implicit FTPS the TLS session is negotiated as soon as the client connects, before the FTP greeting. RFC 4217 defines explicit FTPS, where the client sends AUTH TLS on the regular FTP control connection.
Which port carries FTPS data connections?→
IANA assigns port 989 (ftps-data) to the FTP data connection over TLS/SSL, paired with 990 for the control connection.
Which vulnerabilities affect the service on port 990?→
This database lists 3 CVEs related to FTPS (implicit), 3 of them confirmed as exploited by CISA. Examples: CVE-2025-47813, CVE-2025-47812, CVE-2021-35211.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 990 is not guaranteed to be FTPS (implicit). Exploited-in-the-wild data from the CISA KEV catalog (CC0).