151
Summary
- // if you see it open
- Reportedly included authentication/encryption provisions in its design (RFC 1022), unlike SNMPv1's plaintext community strings (single-source characterization, not independently re-verified against RFC 1022 text). No CVEs and no Shodan/Censys exposure telemetry specific to port 151 were found, and the measured nmap-services open-frequency sits at the dataset's lowest nonzero step; a live response today would be anomalous and worth investigating as misconfiguration, non-standard reuse, or scanner noise rather than genuine HEMS activity.
- // analyst note
- a live response on port 151 today would be anomalous; treat as misconfiguration, non-standard service reuse, or scanner noise rather than genuine HEMS traffic.
About port 151/tcp.
Port 151 is registered with IANA — on both TCP and UDP — under the service name hems, described simply as "HEMS." The IANA registry's Reference field for this entry is blank, so no RFC is formally cited by IANA itself, even though the protocol behind the name is well documented elsewhere. HEMS (High-level Entity Management System) was a mid-1980s experimental Internet network-management protocol suite, laid out across RFC 1021 (overview, October 1987), RFC 1022 (the HEMP transport/management protocol), RFC 1023 (a management language), and RFC 1024 (variable definitions), with an updated monitoring-and-control language added later in RFC 1076 (November 1988). It was one of several competing proposals — alongside SGMP, which evolved into SNMP, and the OSI-derived CMIS/CMIP — put forward to solve gateway and host monitoring on the growing Internet. The IETF ultimately adopted SNMP as the interim standard, and HEMS was withdrawn rather than deployed; RFC 1021 today carries the formal "Legacy" status, meaning it has no standing in the current IETF process. No known software, service, or malware family is documented as using port 151 in practice, and no CVEs for the port were found in this pass; the nmap-services dataset puts 151/tcp at an observed open-frequency of approximately 0.000013, its lowest nonzero step — consistent with a protocol that never left the experimental stage rather than one that is deliberately hidden. One secondary source characterizes HEMS as having built-in authentication and encryption provisions (via RFC 1022) that predated SNMPv1's plaintext community-string weakness, though that claim was not independently verified against the RFC text itself here. A responsive port 151 today would be unusual and worth investigating as a misconfiguration, non-standard reuse, or scanner artifact rather than genuine HEMS traffic.
- IANA assignment
hems— "HEMS"; reference field blank (no RFC cited by IANA); dual-registered 151/tcp + 151/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry- Range class
- well-known (0–1023)
- Prevalence
- nmap-services observed open-frequency 151/tcp ≈ 0.000013 — the dataset's lowest nonzero step [Confirmed] — nmap-services dataset; sibling 151/udp ≈ 0.000412, some thirty-two times higher. Both negligible; a protocol that was withdrawn before deployment
Primary use
HEMS (High-level Entity Management System), a defunct 1980s experimental Internet network-management protocol suite defined in RFC 1021 (overview, Oct 1987), RFC 1022 (HEMP protocol), RFC 1023 (management language), RFC 1024 (variable definitions), and RFC 1076 (updated monitoring/control language, Nov 1988)
Common software
Unknown / none identified — no current or historical implementations listening on port 151 could be verified [Unknown]
- Assignee / contact / registration date / modification date
- Unknown — all blank in the cached IANA registry row, not fabricated [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (lines 379-380)
- Standards history
- competed with SGMP (which evolved into SNMP) and OSI CMIS/CMIP as candidate Internet network-management standards; IETF adopted SNMP instead and HEMS was withdrawn; RFC 1021 carries formal "Legacy" status [Likely] — RFC Editor / datatracker.ietf.org
- Current relevance and exposure
- no CVEs and no 2024–2026 Shodan/Censys exposure telemetry specific to port 151 were found; the one measured figure, nmap-services' floor-level open-frequency, is consistent with an obsolete, essentially unused protocol rather than concealment [Likely] — single secondary source, connected.app
- Security context
- reportedly included authentication/encryption provisions in its design (RFC 1022), unlike SNMPv1's plaintext community strings — single-source characterization, RFC 1022 text itself not independently re-checked in this pass [Likely] — connected.app
- Analyst note
- a live response on port 151 today would be anomalous; treat as misconfiguration, non-standard service reuse, or scanner noise rather than genuine HEMS traffic.
About port 151/udp.
Port 151 is registered with IANA — on both UDP and TCP — under the service name hems, described simply as "HEMS." The registry's Reference field for the UDP row is blank, so IANA itself cites no RFC, though the protocol behind the shared name is documented elsewhere. HEMS (High-level Entity Management System) was a mid-1980s experimental Internet network-management protocol suite spread across RFC 1021 (overview, October 1987), RFC 1022 (the HEMP transport/management protocol), RFC 1023 (a management language), and RFC 1024 (variable definitions), with an updated monitoring-and-control language added later in RFC 1076 (November 1988). None of these documents describe a UDP-specific transport variant distinct from the TCP-based HEMP session model; IANA's dual-listing on 151/tcp and 151/udp appears to be a registry-level reservation of the name rather than evidence of a separately specified UDP protocol. HEMS competed with SGMP (which evolved into SNMP) and OSI CMIS/CMIP for adoption as the Internet's network-management standard; the IETF chose SNMP, HEMS was withdrawn, and RFC 1021 now carries formal "Legacy" status. No verified software, service, or malware family is documented as using 151/udp specifically. A low-authority auto-generated ports directory (portsmaster.net) claims the port is used by an "IDIG protocol," which conflicts with the IANA record and reads as templated content rather than a verified fact; a similarly templated warning on auditmypc.com that the port "has been used by Trojans or viruses" is boilerplate applied broadly across many ports on that site, not a port-151-specific finding. A live response on 151/udp today would be anomalous and worth treating as misconfiguration, non-standard reuse of a defunct name, or scanner/malware noise rather than genuine HEMS traffic.
- IANA assignment
hems— "HEMS"; reference field blank (no RFC cited by IANA); dual-registered 151/tcp + 151/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (row 380); IANA Service Name and Transport Protocol Port Number Registry- Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- nmap-services observed open-frequency 151/udp ≈ 0.000412 (very low — roughly 4 in 10,000 scanned hosts in the nmap-services sample); the dual-registered 151/tcp side is rarer still at ≈ 0.000013 [Confirmed] — nmap-services dataset
- Related ports
- 151/tcp (identical
hemsIANA registration; sibling entry) [Confirmed]
Primary use
HEMS (High-level Entity Management System), a defunct 1980s experimental Internet network-management protocol suite defined in RFC 1021 (overview, Oct 1987), RFC 1022 (HEMP protocol), RFC 1023 (management language), RFC 1024 (variable definitions), and RFC 1076 (updated monitoring/control language, Nov 1988)
Common software
Unknown / none identified — no current or historical implementation listening on 151/udp was verified; one low-authority site's "IDIG protocol" claim conflicts with the IANA record and is not relied on
- Assignee / contact / registration date / modification date
- Unknown — all blank in the cached IANA registry row, not fabricated [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (row 380)
- UDP-specific transport detail
- no UDP-specific specification text was found; RFC 1021 describes the HEMP session model without a distinct UDP variant, so the udp registration appears to be a name reservation alongside the tcp entry rather than a separately specified protocol [Likely] — RFC 1021 (rfc-editor.org)
- Standards history
- competed with SGMP (which evolved into SNMP) and OSI CMIS/CMIP as candidate Internet network-management standards; IETF adopted SNMP instead and HEMS was withdrawn; RFC 1021 carries formal "Legacy" status [Likely] — RFC Editor / datatracker.ietf.org
- Current relevance and exposure
- no CVEs specific to 151/udp were found, and beyond the nmap-services open-frequency figure no 2024–2026 scan/exposure telemetry was located; consistent with an obsolete, essentially unused protocol rather than concealment [Likely] — single secondary source, connected.app
- Security context
- templated "used by Trojans or viruses" warnings on generic port-checker sites are boilerplate applied across many ports, not a port-151-specific verified incident, and are not treated as a confirmed threat association here [Unknown] — auditmypc.com (low-confidence template)
- Analyst note
- a live response on 151/udp today would be anomalous; treat as misconfiguration, non-standard service reuse, or scanner noise rather than genuine HEMS traffic.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| hems | UDP | — | 0.04% |
| hems | TCP | — | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.