40
Summary
- // if you see it open
- No known CVEs and no documented malware family associated with port 40/tcp. Risk is context-dependent: because no standard service binds here, a process listening on 40/tcp on a public host is anomalous and warrants investigation. It may reflect custom, proprietary, or opportunistic use. The port assignment itself carries no inherent vulnerability.
- // analyst note
- Port 40 is unassigned in both the historical RFC 1700 and the current IANA registry. There is no canonical service; treat any open 40/tcp as anomalous and investigate the listening process rather than assuming a known protocol.
About port 40/tcp.
Port 40/tcp is listed as Unassigned in the IANA Service Name and Transport Protocol Port Number Registry: the service-name field is blank, there is no assignee or contact, and the Reference column is empty (no RFC or other IANA reference is cited). The same Unassigned status applies to 40/udp, so neither transport at port 40 carries a registered service. This is consistent with the historical assigned-numbers record: RFC 1700 (Reynolds & Postel, October 1994) lists port 40 explicitly as "Unassigned" for both TCP and UDP. For orientation, the registered neighbours are port 39/tcp (rlp, Resource Location Protocol) and port 41/tcp (graphics), so port 40 sits as a gap between two assigned well-known numbers. No mainstream or well-documented software is known to bind canonically to port 40/tcp — no vendor documentation, open-source project, or authoritative security reference was found that names a default application here. Public-internet visibility is low: the SANS Internet Storm Center port page for port 40 shows a green threat level with only sporadic, low-volume scanner activity, no user-submitted incident reports, and no linked CVEs. There is no documented malware family or exploitation pattern specific to port 40/tcp. Because the port is unassigned, the analyst takeaway is that any service found listening on 40/tcp on a public host is non-standard and worth investigating — it may be a custom, proprietary, or opportunistic binding rather than a known protocol — but the port assignment itself carries no inherent vulnerability.
- IANA assignment
- Unassigned — service-name field blank; no assignee/contact; Reference column blank (no RFC cited); 40/udp likewise Unassigned [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (the IANA Service Name and Transport Protocol Port Number Registry, lines 87-88; https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.csv)
- Range class
- well-known (0–1023)
- Prevalence
- low-volume, sporadic internet scanning only; SANS ISC threat level green, no user-submitted reports [Likely] — https://isc.sans.edu/port.html?port=40
- Related ports
- 39/tcp (
rlp, Resource Location Protocol) and 41/tcp (graphics) — the registered neighbours bracketing this unassigned gap
Primary use
none — no IANA-registered service or protocol; listed "Unassigned" in RFC 1700 (Oct 1994) for TCP and UDP
Other/unofficial uses
Unknown — no mainstream software documented as canonically binding port 40/tcp
Security implications
no known CVEs and no documented malware association; risk is context-dependent — because no standard service binds here, a listener on 40/tcp on a public host is anomalous and warrants investigation
Typically seen on
no standard host class — an open 40/tcp is non-standard and may indicate custom/proprietary or opportunistic use
- Analyst note
- Port 40 is unassigned in both the historical RFC 1700 and the current IANA registry. There is no canonical service; treat any open 40/tcp as anomalous and investigate the listening process rather than assuming a known protocol.
About port 40/udp.
Port 40/udp is listed as Unassigned in the IANA Service Name and Transport Protocol Port Number Registry: the service-name field is blank, there is no assignee or contact, and the Reference column is empty (no RFC or other IANA reference is cited). The same Unassigned status applies to 40/tcp, so neither transport at port 40 carries a registered service. This matches the historical assigned-numbers record — RFC 1340 (Reynolds & Postel, July 1992) and the later RFC 1700 (Reynolds & Postel, October 1994) both list port 40 as "Unassigned" for TCP and UDP — and no subsequent RFC has assigned a service here. For orientation, the registered neighbours are port 39/udp (rlp, Resource Location Protocol) and port 41 (graphics), so port 40 sits as a gap between two assigned well-known numbers; Wikipedia's port-number list skips 40 entirely, jumping from 39 to 41. No mainstream or well-documented software is known to bind canonically to port 40/udp — no vendor documentation, open-source project, or authoritative security reference names a default application here. Public-internet visibility is low: Nmap's nmap-services file carries no UDP open-frequency entry for 40/udp (only a low-frequency TCP row exists), which indicates it is rarely observed open in internet-wide scans. UDP services are intrinsically harder to fingerprint than TCP because an unanswered probe is ambiguous (open vs filtered), so an absence of scan data does not by itself prove the port is unused — but combined with the lack of any registered service it makes a listener on 40/udp unusual. No documented malware family or CVE is specific to port 40/udp. The analyst takeaway is that any service found responding on 40/udp on a public host is non-standard and worth investigating — it may be a custom, proprietary, or opportunistic binding rather than a known protocol — while the port assignment itself carries no inherent vulnerability.
- IANA assignment
- Unassigned — service-name field blank; no assignee/contact; Reference column blank (no RFC cited); 40/tcp likewise Unassigned [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (the IANA Service Name and Transport Protocol Port Number Registry, line 88; https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.csv)
- Range class
- well-known (0–1023)
- Prevalence
- rarely observed; Nmap
nmap-servicescarries no UDP open-frequency entry for 40/udp (only a low-frequency TCP row) [Likely] — https://nmap.org/book/nmap-services.html - Related ports
- 39/udp (
rlp, Resource Location Protocol) and 41 (graphics) — the registered neighbours bracketing this unassigned gap; 40/tcp (the Unassigned TCP counterpart)
Primary use
none — no IANA-registered service or protocol; listed "Unassigned" for TCP and UDP in RFC 1340 (Jul 1992) and RFC 1700 (Oct 1994)
Other/unofficial uses
Unknown — no mainstream software documented as canonically binding port 40/udp
Security implications
no known CVEs and no documented malware association; risk is context-dependent — because no standard service binds here, a listener on 40/udp on a public host is anomalous and warrants investigation (UDP also being harder to fingerprint than TCP)
Typically seen on
no standard host class — a responsive 40/udp is non-standard and may indicate custom/proprietary or opportunistic use
- Analyst note
- Port 40 is unassigned in both the historical assigned-numbers RFCs (1340/1700) and the current IANA registry. There is no canonical service; treat any responsive 40/udp as anomalous and investigate the listening process rather than assuming a known protocol.