437
Summary
- // typical exposure
- Anomalous (rarely legitimately open) — comscm has no published protocol specification, no documented current software implementation, and negligible observed prevalence, so a live listener on 437/tcp does not correspond to any known legitimate use and warrants investigation.
- // analyst note
- comscm has no published protocol specification and no documented current software; a responsive 437/tcp does not match any known legitimate use and merits investigation.
- // if you see it open
- No CVE or named malware family is documented against port 437 as of an August 2026 search, and it does not appear on Fortinet's list of commonly targeted/scanned ports. Generic port-directory sites (e.g. AuditMyPC) carry a template disclaimer stating that a red 'flagged' coloring does not itself indicate active threat use; an August 2026 check of the port-437-specific verdict page returned only the site's generic template rather than port-specific content, so it is not treated as evidence either way. Because no protocol specification or current software implementation is documented anywhere, a responsive 437/tcp does not correspond to any known legitimate deployed use and should be treated as anomalous and investigated.
About port 437/tcp.
Port 437/tcp is IANA-registered to the service name comscm, but no protocol specification or deployed software is documented anywhere; nothing suggests a legitimate reason for it to be reachable from the public internet, and a responsive listener should be treated as anomalous rather than routine.
IANA lists 437 on both TCP and UDP as comscm, with assignee [Jim_Teague] and a blank Reference field — no RFC or protocol writeup accompanies the entry. The registry's Description column duplicates the bare service name with no further elaboration, so even the meaning of the acronym is undocumented.
RFC 1700 records the original registration contact at a Digital Equipment Corporation address, tying the assignment to DEC. No specific DEC product, deployment, or later software has been documented as using the port, so this establishes provenance only, not an active use case.
An August 2026 search found no vendor documentation, blog post, or forum thread naming software that generates traffic on 437/tcp, and the port does not appear on Fortinet's list of commonly targeted or scanned ports. Measured prevalence in the nmap-services scan corpus is negligible: an open-frequency of about 0.0025% on TCP and 0.074% on UDP.
- IANA assignment
comscm— Description column duplicates the service name with no elaboration; reference (blank — no RFC cited); assignee[Jim_Teague]; dual-registered 437/tcp + 437/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry comscm 437/tcp- Range class
- well-known (0–1023) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry comscm 437/tcp
- Registration contact
- RFC 1700 records the original registration contact at a Digital Equipment Corporation address, tying the entry to DEC; the IANA registry itself lists only the assignee name
[Jim_Teague]with no contact address; no later product or deployment is documented[Likely] — https://www.freesoft.org/CIE/RFC/1700/4.htm - Prevalence
- nmap-services open-frequency 437/tcp ≈ 0.000025 (~0.0025%); 437/udp ≈ 0.000741 (~0.0741%) [Confirmed] — this site's own tooling
- Related ports
- none documented — no sibling/paired port relationship found in the registry entry [Unknown] — the IANA Service Name and Transport Protocol Port Number Registry comscm 437/tcp
Primary use
Unknown — no RFC, protocol writeup, or descriptive text is published beyond the bare service-name registration
Other/unofficial uses
none found, as of an August 2026 search (t1shopper.com, adminsub.net, and SpeedGuide listings checked; no software sightings found) [Unknown]
Security implications
not on Fortinet's list of commonly targeted/scanned ports; no CVE or named malware family documented as of an August 2026 search; generic "flagged" boilerplate on port-directory sites is not treated as evidence
Typically seen on
Unknown — bare registration only, no deployment history documented; treat a responsive 437/tcp as anomalous
- Analyst note
- comscm has no published protocol specification and no documented current software; a responsive 437/tcp does not match any known legitimate use and merits investigation.
About port 437/udp.
Port 437/udp is IANA-registered to the service name comscm, but no protocol specification, RFC, or deployed software has been documented anywhere; nothing establishes a legitimate reason for it to be reachable from the public internet, so a responsive UDP listener should be treated as anomalous rather than routine.
IANA lists 437 as comscm on both TCP and UDP, with assignee [Jim_Teague] and a blank Reference field — no RFC accompanies the entry on either transport. The registry's Description column repeats the bare service name with no further elaboration, so even what the acronym stands for is undocumented.
An August 2026 search found no vendor documentation, blog post, or forum thread that credibly identifies software generating traffic on 437/udp. Port-lookup aggregator sites name candidates such as 'Fujitsu Siemens NQA' or 'SMDI', but these are templated, mutually inconsistent, and uncorroborated by any primary source, so they are not reported as fact here.
Measured prevalence in the nmap-services scan corpus is low but nonzero: an open-frequency of about 0.0741% on UDP, roughly thirty times the 0.0025% measured on TCP. No CVE or malware family is documented against the port as of an August 2026 search, and a port-directory disclaimer page (AuditMyPC) could not be rendered to confirm its own verdict line, so it is not cited as evidence either way.
- IANA assignment
comscm— Description column duplicates the service name with no elaboration; reference (blank — no RFC cited); assignee[Jim_Teague]; no Registration or Modification Date recorded; dual-registered 437/tcp + 437/udp[Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry comscm 437/udp- Range class
- well-known (0–1023) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry comscm 437/udp
- Prevalence
- nmap-services open-frequency 437/udp ≈ 0.000741 (~0.0741%); 437/tcp ≈ 0.000025 (~0.0025%) [Confirmed] — this site's own tooling
- Related ports
- none documented — no sibling/paired relationship found beyond the shared 437/tcp + 437/udp dual-registration itself [Unknown] — the IANA Service Name and Transport Protocol Port Number Registry comscm 437/udp
Primary use
Unknown — no RFC, protocol writeup, or descriptive text is published beyond the bare service-name registration
Other/unofficial uses
Unknown, as of an August 2026 search — aggregator sites portsmaster.net and ports.my-addr.com name candidates ('Fujitsu Siemens NQA', 'SMDI') but disagree with each other and are not corroborated by a primary source, so none is reported as fact [Unknown]
Security implications
no CVE or named malware family documented as of an August 2026 search; AuditMyPC's UDP port-437 page carries only its standard template disclaimer, and the page's own verdict line could not be independently rendered to confirm, so it is not treated as evidence either way
Typically seen on
Unknown — bare registration only, no deployment history documented; treat a responsive 437/udp as anomalous
- Analyst note
- comscm has no published protocol specification and no documented current software on either transport; a responsive 437/udp does not match any known legitimate use and merits investigation.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| comscm | UDP | — | 0.07% |
| comscm | TCP | — | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.