Network port detail · UDP/TCP

216

CAIlic
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
No vulnerability confirmed as bound specifically to port 216. A related CA License Server/Client buffer-overflow family (CVE-2005-0581, CVE-2005-0582, CVE-2005-0583, disclosed 2005-03-02) exists, but its documented Metasploit exploit modules (calicserv_getconfig, calicclnt_getconfig) target default ports 10202/10203, not 216 — do not attribute that CVE family to this port.
// analyst note
an open 216/tcp is most plausibly a legacy CA licensing daemon rather than an actively maintained service; do not conflate any observed exploitation attempt with the CVE-2005-0581 family, which targets 10202/10203, not 216.
[ 01 ] — Context

About port 216/tcp.

Updated  ·  Confidence: Medium

Port 216/tcp is registered with IANA under the service name CAIlic, described as "Computer Associates Int'l License Server," with assignee and contact both listed as Chuck Spitz. The registry carries no RFC or other reference for this entry, and the Registration Date, Modification Date, Service Code, Unauthorized Use Reported, and Assignment Notes columns are all blank in the canonical IANA CSV — there is nothing to cite there beyond the fact of the blank. Port 216/udp carries an identical registration (same service name, description, assignee, and contact), so the assignment is a dual TCP/UDP one rather than TCP-specific. Functionally, CAIlic is a legacy license-checkout daemon tied to older Computer Associates (CA) enterprise software — CA's product portfolio has since been absorbed into Broadcom, and this specific port-216 service does not correspond to any CA product still actively marketed. A note of caution surfaced during research: CA License Server/Client did have real, disclosed buffer-overflow vulnerabilities (CVE-2005-0581, CVE-2005-0582, CVE-2005-0583, publicly disclosed 2005-03-02), but the documented Metasploit exploit modules for those flaws (calicserv_getconfig, calicclnt_getconfig) target default ports 10202 and 10203 — not 216 — so that CVE family should not be attributed to this port without further confirmation. The nmap-services dataset does carry a measured open-frequency for this port — 216/tcp at approximately 0.000013, the dataset's lowest nonzero step — but no exploitation telemetry specific to port 216 was located in this pass.

IANA assignment
CAIlic — "Computer Associates Int'l License Server"; reference (blank — no RFC cited in IANA registry); assignee and contact both [Chuck_Spitz]; dual-registered 216/tcp + 216/udp with identical fields [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (lines 534–535), cross-checked against https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml
Range class
well-known (0–1023) [Confirmed]
Prevalence
nmap-services observed open-frequency 216/tcp ≈ 0.000013 — the dataset's lowest nonzero step [Confirmed] — nmap-services dataset; the 216/udp row (named atls in nmap's own table, CAIlic at IANA) is ≈ 0.000461, some thirty-five times higher. Measured exposure is therefore very low, as expected for a discontinued legacy CA daemon; no GreyNoise or Shodan/Censys count specific to port 216 was found [Unknown]
Related ports
10202/tcp and 10203/tcp — the actual default ports for the CA License Server/Client GETCONFIG vulnerabilities (CVE-2005-0581/0582/0583); distinct from and should not be conflated with 216 [Likely] — https://www.rapid7.com/db/modules/exploit/windows/license/calicserv_getconfig/

Primary use

legacy license-management/checkout service for old Computer Associates International (CA, now part of Broadcom) enterprise software — a client-server protocol used to validate and dispense software license tokens [Likely] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml, https://www.speedguide.net/port.php?port=216

Other/unofficial uses

no confirmed unofficial or repurposed uses found; some older CA "lic98"-family license-daemon components have been loosely associated with this service family, but no source ties them specifically to port 216 [Unknown]

Security implications

no vulnerability confirmed as bound specifically to port 216. A related but distinct CA License Server/Client buffer-overflow family exists (CVE-2005-0581, CVE-2005-0582, CVE-2005-0583, disclosed 2005-03-02); the Rapid7 Metasploit modules for those exploits (calicserv_getconfig targeting the server, calicclnt_getconfig targeting the client) document default ports 10202 and 10203, not 216 — do not attribute this CVE family to port 216 [Likely] — https://www.rapid7.com/db/modules/exploit/windows/license/calicserv_getconfig/, https://www.rapid7.com/db/modules/exploit/windows/license/calicclnt_getconfig/

Typically seen on

legacy Windows hosts running older CA (Computer Associates) enterprise licensing infrastructure; not expected on modern deployments

[Likely] — https://www.speedguide.net/port.php?port=216, https://blog.ciaops.com/2007/07/15/computer-associates-ca-licensing/

Malware associations

none found; generic port-lookup aggregators (SpeedGuide, AuditMyPC) report no known trojan/malware association with port 216, though these are unauthoritative secondary sources

[Unknown] — https://www.speedguide.net/port.php?port=216, https://www.auditmypc.com/tcp-port-216.asp
Analyst note
an open 216/tcp is most plausibly a legacy CA licensing daemon rather than an actively maintained service; do not conflate any observed exploitation attempt with the CVE-2005-0581 family, which targets 10202/10203, not 216.
[ 02 ] — Context

About port 216/udp.

Updated  ·  Confidence: Medium

Port 216/udp is registered with IANA as CAIlic, described as "Computer Associates Int'l License Server," with assignee and contact both listed as Chuck_Spitz. The IANA registry carries no Registration Date, Modification Date, or Reference (RFC) value for this entry — a common pattern for older allocations that predate the registry's later date-tracking discipline, and those fields are left blank here rather than guessed. The identical assignment appears one row above at 216/tcp, so the service is formally dual-registered across both transports under the same name and description. CAIlic corresponds to the license-checking component of Computer Associates International's (CA, absorbed into Broadcom in 2018) enterprise software license server/client family — a legacy, largely end-of-life product line. That family has a documented history of remote code execution flaws: CVE-2005-0581, a stack buffer overflow in the GETCONFIG protocol handler, disclosed March 2, 2005, with public Metasploit modules (calicserv_getconfig, calicclnt_getconfig). Those specific published exploits target TCP ports 10202/10203 rather than port 216 itself, so a port-216-specific exploit chain cannot be confirmed from the sources checked — the vulnerability family and the port-216 IANA registration both belong to the same CA license-server product line, but the linkage between the two is inferential, not demonstrated. No internet-wide scanning or exposure telemetry for port 216 was located, and given the product's legacy status, real-world exposure is presumed low but unmeasured.

IANA assignment
CAIlic — "Computer Associates Int'l License Server"; assignee/contact [Chuck_Spitz]; reference blank (no RFC cited in IANA registry); dual-registered 216/tcp + 216/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry line 535 (and line 534 for 216/tcp); cross-checked against https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt
Registration/modification date
blank in the IANA source for this legacy entry — left null rather than invented [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry line 535
Range class
well-known (0–1023) [Confirmed]
Related ports
216/tcp (identical dual registration, same assignee/description) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry line 534

Primary use

legacy CA (now Broadcom) license-checking protocol used by the CA License Server/Client family bundled with older Computer Associates enterprise software

[Likely] — https://www.rapid7.com/db/modules/exploit/windows/license/calicserv_getconfig/

Common software

CA License Server / CA License Client binaries shipped with older CA (Broadcom) enterprise packages; no unrelated modern software found using this port

[Likely] — https://www.rapid7.com/db/modules/exploit/windows/license/calicserv_getconfig/

Security implications

CA License Client/Server GETCONFIG handler has a documented remote stack buffer overflow, CVE-2005-0581 (disclosed 2005-03-02), with public Metasploit modules; however the specific published exploit (exploit-db #16744) targets TCP 10202/10203, not port 216, so a port-216-specific exploit vector is Unknown/unconfirmed [Likely (vulnerability family exists) / Unknown (port-216-specific exploit)] — https://www.rapid7.com/db/modules/exploit/windows/license/calicserv_getconfig/, https://www.exploit-db.com/exploits/16744, https://www.computerweekly.com/news/1280096516/Exploit-code-targets-critical-CA-flaws

Exposure/scanning telemetry

no internet-wide scan or exposure statistics for port 216 were located in this research pass [Unknown]

Typically seen on

legacy/EOL Computer Associates (Broadcom) enterprise license-server deployments; presumed rare today given end-of-life status (inference, not a sourced count) [Likely]

// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
atls UDP Access Technology License Server 0.05%
atls TCP CAIlic 0.00%
IANA name
CAIlic
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.