Network port detail · UDP/TCP

480

Iafdbase
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// typical exposure
Anomalous (rarely legitimately open) — No documented protocol, vendor, or legitimate deployment pattern exists for 480/tcp under either its IANA name ("iafdbase") or its nmap-services name ("loadsrv"), and open-frequency telemetry shows it almost never open, so any listener here is a fingerprinting or anomaly signal rather than expected service traffic.
// analyst note
Two different service names appear for this port depending on the data source (IANA's iafdbase vs. nmap-services' loadsrv on the TCP side) and neither maps to a documented protocol or named application — do not assume either label identifies the actual software behind an open port 480.
// if you see it open
No CVE referencing 480/tcp is recorded in the NVD as of an August 2026 search. No malware/trojan association was found. SANS ISC's port-480 page shows only routine internet background-scan noise, not a documented targeted campaign. The port is almost never observed open and has no documented legitimate protocol, so real traffic on it should be treated as anomalous and investigated.
[ 01 ] — Context

About port 480/tcp.

Updated  ·  Confidence: Low

Port 480/tcp carries no documented protocol; it is a sparsely-used registered port with no evidence of legitimate public-facing use, so it should generally stay internal-only or simply closed rather than exposed to the internet. IANA registers 480 on both TCP and UDP as iafdbase, assignee Rick_Yazwinski, with a blank Reference column and no description beyond the name itself.

The companion port 479 is registered under the name iafserver, suggesting the pair was meant to work together, but the 479 rows carry no assignee at all — IANA's Assignee and Contact columns for iafserver are empty, unlike 480's iafdbase rows which name Rick_Yazwinski. So the iafserver/iafdbase pairing rests on the adjacent registered names and shared numbering alone, not on a shared registrant. IANA publishes no RFC or specification for either, and no protocol document describes what "iafdbase" actually does on the wire.

Separately, the nmap-services corpus (used by Nmap and mirrored in this site's port-data artifact) labels 480/tcp specifically as loadsrv — a different name than the IANA iafdbase registration — while keeping iafdbase as the label for 480/udp. Neither name is tied to a known, named application in any source found; a claimed link to Software AG's unrelated "Integrated Authentication Framework" product is unverified speculation and is not asserted here.

Real-world visibility is minimal: nmap-services open-frequency for 480/tcp is about 0.0013%, and SANS ISC's port-480 tracker shows only routine internet background-scan noise rather than a documented targeted campaign. No CVE referencing port 480/tcp is recorded in the NVD as of an August 2026 search, and no malware/trojan association was found for it as of the same search.

IANA assignment
iafdbase — description "iafdbase"; reference (blank); assignee Rick_Yazwinski; dual-registered 480/tcp + 480/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry iafdbase 480/tcp; the IANA Service Name and Transport Protocol Port Number Registry iafdbase 480/udp
Range class
system/well-known (0–1023) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry iafdbase 480/tcp
Prevalence
nmap-services open-frequency 480/tcp = 0.000013 (~0.0013%); 480/udp = 0.000461 (~0.046%) [Confirmed] — this site's own tooling
Related ports
479/tcp,udp (iafserver, no assignee recorded — the pairing with 480's iafdbase rests on adjacent naming, not a shared registrant) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry iafserver 479/tcp

Primary use

Unknown — IANA lists the name pair only, with no RFC or protocol description; the companion 479/tcp,udp is registered iafserver with no assignee recorded [Confirmed registration / Unknown protocol] — the IANA Service Name and Transport Protocol Port Number Registry iafdbase 480/tcp

Other/unofficial uses

nmap-services labels 480/tcp specifically as loadsrv (distinct from the IANA iafdbase name, which nmap-services applies to 480/udp instead); no vendor/software identity confirmed for either label

[Likely] — this site's own tooling

Security implications

no CVE, no confirmed malware association, and only routine background scan noise observed; the port is essentially unused and undocumented, so an unexpected listener merits investigation

[Likely] — https://isc.sans.edu/data/port/480

Typically seen on

not typically seen open on any known platform; treat any hit as anomalous [Unknown]

Analyst note
Two different service names appear for this port depending on the data source (IANA's iafdbase vs. nmap-services' loadsrv on the TCP side) and neither maps to a documented protocol or named application — do not assume either label identifies the actual software behind an open port 480.
[ 02 ] — Context

About port 480/udp.

Updated  ·  Confidence: Low

Port 480/udp carries the IANA-registered service name iafdbase, but no confirmed real-world application or published protocol spec exists for it, so it should not be treated as a legitimate service to expose to the public internet — an open 480/udp is best read as anomalous and worth investigating rather than trusted as routine.

IANA lists 480/udp as iafdbase, assignee Rick Yazwinski, with a blank Reference field and no Registration or Modification date on file. IANA registers iafdbase on both 480/tcp and 480/udp — there is no separate loadsrv entry anywhere in the IANA registry. The name loadsrv (description "iafdbase") is a label carried in the nmap-services database, mirrored in this repo's this site's own tooling, for 480/tcp; it is a database naming discrepancy between nmap-services and IANA, not a second, overlapping, or legacy duplicate IANA registration.

No vendor documentation, RFC, or product page describing an actual wire protocol for iafdbase was found. One Experts Exchange forum thread ("What is iafserver and iafdbase (ports 479 & 480)") shows at least one administrator investigated this exact port pairing after seeing unexplained traffic, but the thread's content could not be retrieved (403 Forbidden), so no software can be credibly attributed from it.

The port is not listed on Gary Kessler's maintained Bad TCP/UDP Ports (trojan) list as of an August 2026 search. SANS Internet Storm Center shows only low, green-level background scanning on the port, consistent with routine internet-wide sweeps rather than a targeted campaign.

IANA assignment
iafdbase — description "iafdbase"; Reference field blank; assignee Rick_Yazwinski; IANA registers iafdbase on both 480/tcp and 480/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry iafdbase 480/tcp; the IANA Service Name and Transport Protocol Port Number Registry iafdbase 480/udp
Range class
well-known (0–1023), IANA "system" range [Confirmed] — this site's own tooling
Prevalence
this site's own tooling open-frequency 480/udp (iafdbase) = 0.000461; sibling 480/tcp (nmap-services label loadsrv) = 0.000013 [Confirmed] — this site's own tooling
Related ports
479/tcp+udp (iafserver, believed paired by naming convention with iafdbase; pairing not independently verified beyond the registry name and one unresolved forum thread) [Unknown]

Primary use

no confirmed protocol or application; the bare IANA name is the only documented fact

[Unknown] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?page=9

Other/unofficial uses

none confirmed; one unresolved forum thread references the 479/480 pairing but its content could not be fetched (403)

[Unknown] — https://www.experts-exchange.com/questions/21637972/Whatb-is-iafserver-and-iafdbase-ports-479-480.html

Security implications

not on Gary Kessler's Bad Ports (trojan) list as of August 2026; SANS ISC shows low, green-level, non-targeted scanning; no CVE found tied to this port or service as of an August 2026 search

[Likely] — https://www.garykessler.net/library/bad_ports.html, https://isc.sans.edu/data/port/480

Typically seen on

no confirmed hosts or products; observed activity is more consistent with scanning noise than a deployed service [Unknown]

Analyst note
An open 480/udp with no confirmed application behind it should be treated as anomalous — investigate the source rather than assume a legitimate service.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
iafdbase UDP 0.05%
loadsrv TCP iafdbase 0.00%
IANA name
iafdbase
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.