Network port detail · UDP/TCP

436

Dna-cml
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
No CVE or named malware family is documented for 436/tcp as of an August 2026 search. Generic port-directory sites (e.g. auditmypc.com) carry only templated caution text repeated across many ports, not evidence of a specific threat. The one third-party sighting (a Juniper AppID signature) gives no functional description and appears to mirror the bare IANA registration rather than report observed behavior. With no documented protocol purpose or confirmed current software, an open 436/tcp has no established legitimate reason to be reachable and should be treated as unidentified rather than assumed benign.
// analyst note
treat an open port 436 as unidentified rather than assumed benign — no source establishes a legitimate current deployment or documented protocol behavior.
[ 01 ] — Context

About port 436/tcp.

Updated  ·  Confidence: Low

Port 436/tcp is IANA-registered under the service name dna-cml, but no RFC, protocol specification, or vendor documentation describes what the service actually does — so whether it belongs on the public internet cannot be established from available sources, and any live listener should be treated as unidentified rather than assumed safe.

IANA's registry confirms the bare facts: service name dna-cml, a description field that simply repeats the name as "DNA-CML," assignee and contact Dan Flowers, and a blank Reference column — no RFC backs the entry. It is dual-registered on both 436/tcp and 436/udp, and no registration or modification date is published.

The only third-party sighting found is a Juniper Networks Application Identification (AppID) signature named "DNA-CML," which groups TCP/UDP 436 with several unrelated ports — including TCP/434, separately registered by IANA as mobileip-agent — under category Infrastructure, sub-category miscellaneous, at a low risk score. Juniper's entry gives no functional description and appears to mirror the bare IANA registration rather than report independently observed behavior.

No CVE or named malware family is documented against port 436, and generic port-lookup sites (e.g., auditmypc.com) carry only templated caution text that is not treated as evidence of a specific threat. nmap-services records an open-frequency of exactly 0 for 436/tcp (sampled, not observed open) and about 0.0004 for 436/udp — both negligible.

IANA assignment
dna-cml — "DNA-CML"; reference (blank — no RFC cited in IANA registry); assignee Dan Flowers; dual-registered 436/tcp + 436/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry dna-cml 436/tcp; cross-checked https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.csv
Range class
well-known (0–1023) [Confirmed]
Prevalence
nmap-services open-frequency (this site's own tooling): 436/tcp = 0.000000 (present in the dataset with zero observed open-frequency, not an absence of data); 436/udp ≈0.000379 [Confirmed] — this site's own tooling
Related ports
none confirmed — the Juniper signature's grouping of TCP/434 is a classification artifact, not a protocol relationship (434 is separately registered as mobileip-agent, Mobile IPv4 signaling) [Unknown]

Primary use

registered for "DNA-CML" per IANA; no protocol specification, RFC, or independent documentation of the service's function was found as of an August 2026 search

[Unknown] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.csv

Other/unofficial uses

Juniper Networks AppID signature "DNA-CML" groups TCP/UDP 436 with several unrelated ports (including TCP/434, separately IANA-registered as mobileip-agent) under category Infrastructure/miscellaneous, risk level 2 — reads as a mirror of the IANA registration rather than an independent report of observed traffic

[Likely] — https://www.juniper.net/us/en/threatlabs/application-signatures/detail.DNA-CML.html

Security implications

no CVE or named malware family documented for 436/tcp as of an August 2026 search; auditmypc.com's templated caution text is excluded as evidence per the site's known boilerplate pattern [Unknown/Likely]

Typically seen on

no confirmed hosts or software; an open listener would be atypical and worth investigating [Unknown]

Analyst note
treat an open port 436 as unidentified rather than assumed benign — no source establishes a legitimate current deployment or documented protocol behavior.
[ 02 ] — Context

About port 436/udp.

Updated  ·  Confidence: Low

Port 436/udp carries the IANA-registered name dna-cml, but nothing beyond that bare label is documented — no protocol specification, no identified software, and no evidence of real-world deployment — so there is no confirmed service to certify as safe for exposure to the public internet. A live listener on 436/udp is best treated as unidentified and worth investigating rather than assumed to be routine traffic.

IANA's Service Names and Port Numbers registry dual-registers port 436 on both TCP and UDP under the identical name dna-cml, with the Description field reading only "DNA-CML" — a restatement of the name rather than an explanation of function. Assignee and contact are both recorded as [Dan_Flowers], an individual rather than a company, and the Registration Date, Modification Date, and Reference columns are all blank; no RFC backs the assignment.

No independent source explains what dna-cml does or names software that uses it. General port-lookup aggregator pages mirror the bare IANA listing without adding detail, as of an August 2026 search. Juniper Threat Labs' deep-packet-inspection signature catalog does list a "DNA-CML" entry under a broad Infrastructure/miscellaneous classification, but that is a vendor traffic-tagging label spanning several ports, not confirmation that any specific product generates traffic on 436/udp.

No CVE or named malware family is recorded against port 436 as of the same search. auditmypc.com's per-port scan page did not return a live verdict line for this port during this research — only its generic caveat text came back — so no malware association is drawn from it either way, and no SANS Internet Storm Center scanning data specific to port 436 was found.

IANA assignment
dna-cml — "DNA-CML" (description restates the name, not an expansion); reference blank (no RFC cited); assignee and contact both [Dan_Flowers]; Registration Date and Modification Date blank; dual-registered 436/tcp + 436/udp
[Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (dna-cml 436/udp, dna-cml 436/tcp)
Range class
well-known (0–1023) [Confirmed]
Prevalence
nmap-services open-frequency 436/udp ≈ 0.000379 (~0.04%); 436/tcp ≈ 0.000000 (sampled, not observed open) [Confirmed] — this site's own tooling
Related ports
436/tcp (dual-registered under the identical name dna-cml, same assignee) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (dna-cml 436/tcp)

Primary use

Unknown — no RFC or protocol specification is referenced by IANA, and no independent source expands what dna-cml denotes, as of an August 2026 search

[Unknown] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml

Other/unofficial uses

none confirmed; Juniper Threat Labs lists a "DNA-CML" DPI application signature (Infrastructure/miscellaneous, risk 2) grouping several ports together, but this is a vendor traffic-classification label, not evidence of specific software running on 436/udp

[Unknown] — https://www.juniper.net/us/en/threatlabs/application-signatures/detail.DNA-CML.html

Security implications

no CVE or named malware family recorded against port 436 as of an August 2026 search; auditmypc.com did not return a live per-port verdict line during this research, so no malware association is asserted

[Unknown] — https://www.auditmypc.com/udp-port-436.asp

Typically seen on

Unknown — no confirmed deployment context or software was identified in this research [Unknown]

Analyst note
An open 436/udp has no known protocol, software, or documented legitimate use behind it — treat it as anomalous and investigate rather than assume routine traffic.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
dna-cml UDP 0.04%
dna-cml TCP 0.00%
IANA name
dna-cml
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.