132
Summary
- // if you see it open
- Unknown — no CVE or security advisory identified for a cisco-sys/SYSMAINT service on this port
- // analyst note
- Treat the IANA label as the only confirmed fact for this port; there is no protocol spec to validate observed traffic against, so correlate with device/vendor context rather than assuming standard behavior.
About port 132/tcp.
Port 132/tcp is registered with IANA under the service name cisco-sys, with the description "cisco SYSMAINT." The registration is dual-listed: an identical row exists for 132/udp with the same service name and description, differing only in the transport-protocol column. Beyond that single-line registry entry, the assignment carries essentially no public documentation. IANA's Assignee, Contact, Registration Date, Modification Date, Reference, Service Code, and Assignment Notes columns are all blank for this entry, and no IETF RFC or other protocol specification is associated with it — there is no Reference value to cite, and none should be invented. Web research beyond the registry turned up nothing to fill the gap: no Cisco product manual, technical note, or vendor documentation describing an active "SYSMAINT" service listening on TCP or UDP port 132 was found, and the port does not appear in Wikipedia's list of TCP and UDP port numbers. A handful of low-quality "port lookup" directory sites (SpeedGuide-style aggregators, t1shopper.com, tcp-udp-ports.com, auditmypc.com and similar) simply republish the same one-line IANA entry without adding independent technical detail, so they don't count as corroboration and aren't treated as sources here. No CVE, security advisory, or honeypot report mentioning port 132 in connection with Cisco SYSMAINT was located either. The one measured datum that does exist is Nmap's own service-frequency table, which records 132/tcp at an observed open-frequency of approximately 0.000013 — the lowest nonzero step in that dataset, so the port has been seen open in the wild, but only barely. In short, this is a thinly-documented legacy Cisco IANA registration: the name and one-line description are first-party, verifiable facts, but everything about what the service actually does, whether any Cisco product still implements it, and whether it has ever been exploited is genuinely unknown and should be recorded as such rather than guessed at. Analysts encountering traffic on 132/tcp should treat the IANA label as the only confirmed fact and correlate with the specific device/OS and packet contents rather than assuming a known protocol behavior, since no protocol specification exists to check against.
- IANA assignment
cisco-sys— "cisco SYSMAINT"; reference (blank — no RFC/reference cited in IANA registry); assignee/contact blank; dual-registered 132/tcp + 132/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry- Range class
- well-known (0–1023)
- Prevalence/exposure
- nmap-services observed open-frequency 132/tcp ≈ 0.000013 — the dataset's lowest nonzero step [Confirmed] — nmap-services dataset; sibling 132/udp ≈ 0.000923, some seventy times higher. Beyond that figure, no honeypot data or vulnerability advisory referencing this port was found, and it is not listed in Wikipedia's port-number table [Unknown]
- Related ports
- other single-vendor legacy registrations in the same numeric neighborhood; no specific technical relationship established
Primary use
registered to Cisco as "SYSMAINT" (system maintenance); no IETF RFC or public protocol specification found describing its function
Other/unofficial uses
none found; no vendor documentation or product manual describing an active implementation surfaced in research [Unknown]
Security implications
no CVE or advisory identified for a cisco-sys/SYSMAINT service on this port [Unknown]
Typically seen on
presumably legacy/older Cisco equipment given the "cisco-sys" registration name, but no corroborating documentation confirms current or historical real-world use [Unknown]
- Analyst note
- Treat the IANA label as the only confirmed fact for this port; there is no protocol spec to validate observed traffic against, so correlate with device/vendor context rather than assuming standard behavior.
About port 132/udp.
Port 132/udp is registered with IANA under the service name cisco-sys, with the description "cisco SYSMAINT." The registry's Assignee, Contact, Registration Date, Modification Date, Reference, Service Code, Unauthorized Use Reported, and Assignment Notes fields are all blank for this entry — a common pattern among vendor assignments made in the earlier, less-documented era of the IANA registry, before the registry required fuller metadata for new entries. The assignment is dual: 132/tcp carries the identical service name and description, meaning both transports were assigned together as a pair rather than one being a later addition. No RFC or other reference document is cited for this port, and no current, independently verifiable Cisco product documentation could be located describing an actively used "SYSMAINT" protocol running on this port today; the entry appears to be a legacy vendor registration rather than a specification for a live, documented protocol. RFC 1340 ("Assigned Numbers," October 1992) lists the same tcp/udp 132 mapping, but that document is itself a historical snapshot of the registry rather than a protocol definition, so it should not be cited as the RFC that defines this port's behavior. No exposure-scanning statistics, CVE records, malware associations, or honeypot data specific to 132/udp were identified. Because the port is a blank-metadata legacy Cisco assignment with no confirmed active use, an analyst who observes real-world traffic on 132/udp should treat it primarily as an IANA-registry curiosity and investigate the specific host/context rather than assume a known, currently active Cisco service is responsible.
- IANA assignment
cisco-sys— "cisco SYSMAINT"; reference blank; assignee/contact blank; dual-registered 132/tcp + 132/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (cached IANA registry, CSV line 342); cross-checked against https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt- Range class
- well-known (0–1023) [Confirmed] — IANA registry range convention
- Registration/modification dates
- blank in the registry for this entry; not fabricated as a placeholder, recorded as Unknown [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry; https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt
- IANA reference (RFC)
- none published; the field is blank in the registry and no RFC should be cited as defining this port [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt
- Related ports
- 132/tcp (identical dual registration, same name/description) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
Primary use
legacy Cisco vendor assignment ("SYSMAINT"); no current, independently verifiable protocol specification or active-use documentation found [Likely] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt; historically mirrored in RFC 1340 (1992) https://datatracker.ietf.org/doc/html/rfc1340
Common software
Unknown — no modern Cisco IOS/product manual reference to this port identified in this research pass [Unknown]
Exposure/scanning notes
Unknown — no Shodan/Censys statistics, CVE records, or malware/honeypot associations specific to 132/udp identified; generic third-party port-list sites (e.g. speedguide.net, returned HTTP 403 on fetch attempt) were not used as sources [Unknown]
Typically seen on
Unknown / rare — legacy Cisco-adjacent hosts if present at all; treat any observed traffic as context-dependent rather than a known active service
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| cisco-sys | UDP | cisco SYSMAINT | 0.09% |
| cisco-sys | TCP | cisco SYSMAINT | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.