490
Summary
- // typical exposure
- Anomalous (rarely legitimately open) — micom-pfs is a decades-old legacy registration with no confirmed active use in current environments, so an open 490/tcp is anomalous and warrants investigation rather than routine allowance.
- // analyst note
- An open port 490/tcp has essentially no evidence of legitimate current use — treat it as an anomaly worth investigating (misconfiguration, decoy, or non-standard service) rather than routine traffic.
- // if you see it open
- No CVE referencing port 490 is recorded in the NVD as of 2026-08. auditmypc.com's own verdict line marks the port 'Virus / Trojan: No' as of an August 2026 check. Port 490 is not among commonly targeted/scanned ports called out in general port-scanning security literature (Fortinet cyberglossary). Essentially no independent evidence of live software traffic on this port was found in an August 2026 search; treat an open 490/tcp as an anomaly.
About port 490/tcp.
Port 490/tcp is registered with IANA under the name "micom-pfs," but no confirmed software actively uses this port today; a listener here belongs internal-only at most and is better treated as an anomaly than as an expected public-facing service.
IANA lists 490 as dual-registered on TCP and UDP under "micom-pfs," assignee David Misunas, with a blank reference field and no RFC cited. The name is generally associated with MICOM Systems Inc., a legacy telecom/networking equipment vendor known for concentrators and statistical multiplexers, founded in 1975 and acquired by Philips in 1984; "PFS" likely denotes a MICOM packetized front-end/switching product line, though IANA's registry documents no protocol specification confirming exact semantics.
An August 2026 search found no independent evidence of live traffic on 490/tcp from vendor documentation, forums, or threat-intelligence sources. Third-party port-lookup directories (t1shopper.com, adminsub.net) only echo the IANA registration name rather than reporting observed usage. Juniper's threat-signature database lists a same-named "MICOM-PFS" application signature, but it documents a distinct set of monitored ports (UDP 5246-5247, UDP 3386, UDP 3544, TCP 3386, TCP 434) and cites the IANA 490 registration only as the signature's namesake, not as a live sighting on port 490 itself.
Nmap's open-frequency data records 490/tcp at exactly 0 (sampled, not observed open in the corpus) and 490/udp at approximately 0.000577, both consistent with a dormant legacy registration rather than an actively deployed service.
- IANA assignment
micom-pfs; reference (blank — no RFC cited); assignee David_Misunas; dual-registered 490/tcp + 490/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry micom-pfs 490/tcp- Range class
- well-known (0–1023) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry micom-pfs 490/tcp
- Prevalence
- nmap-services open-frequency 490/tcp = 0 (sampled, not observed open); 490/udp ≈ 0.000577 [Confirmed] — this site's own tooling
- Related ports
- none confidently identified; the Juniper "MICOM-PFS" signature monitors an unrelated port set (UDP 5246-5247, UDP 3386, UDP 3544, TCP 3386, TCP 434) and should not be read as a related-ports cluster for 490 itself[Unknown] — https://www.juniper.net/us/en/threatlabs/application-signatures/detail.MICOM-PFS.html
Primary use
micom-pfs, likely associated with legacy MICOM Systems Inc. telecom/networking equipment (concentrators, packetized front-end/switching products); no RFC or protocol spec on file [Likely] — https://en.wikipedia.org/wiki/Micom, https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.csv
Other/unofficial uses
none found in an August 2026 search [Unknown]
Security implications
no CVE recorded in NVD as of 2026-08; auditmypc.com verdict "Virus / Trojan: No" as of August 2026; not among commonly-scanned ports in general security literature
Typically seen on
no confirmed deployment found; treat as legacy/dormant registration [Unknown]
- Analyst note
- An open port 490/tcp has essentially no evidence of legitimate current use — treat it as an anomaly worth investigating (misconfiguration, decoy, or non-standard service) rather than routine traffic.
About port 490/udp.
Port 490/udp carries the IANA-registered service name micom-pfs; the registry defines no protocol, RFC, or expanded description beyond that bare name, so what actually runs on the port is undocumented. It should not be treated as a service knowingly exposed to the public internet — there is no documented reason for it to be.
IANA lists micom-pfs as dual-registered on both 490/tcp and 490/udp, assigned to David Misunas, with a blank Reference column and no registration or modification date recorded. No RFC or vendor specification is cited anywhere in the registry, which is unusual even among lightly documented legacy port assignments.
The name plausibly traces to Micom Systems, Inc., a 1970s-era networking/telecom equipment vendor later acquired by Philips, but this link is circumstantial — a name match only, with no primary source tying the port-490 registration to a specific Micom product or protocol. A Juniper Networks application-signature page titled "MICOM-PFS" exists but lists a different, non-matching set of ports, so it was not treated as corroborating evidence.
Measured open-frequency in the nmap-services corpus is 0.000577 for 490/udp and exactly 0 for 490/tcp — both effectively negligible. No vendor documentation, blog post, or forum thread was found reporting an application that actually generates traffic on this port, and generic port-lookup aggregator sites only mirror the bare IANA registration without adding usage reports.
- IANA assignment
micom-pfs; reference (blank — no RFC cited); assignee David_Misunas; dual-registered 490/tcp + 490/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry micom-pfs 490/udp- Range class
- well-known (system, 0–1023) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry micom-pfs 490/udp
- Prevalence
- nmap-services open-frequency 490/udp = 0.000577; 490/tcp = 0 [Confirmed] — this site's own tooling (built from nmap-services)
- Related ports
- 490/tcp (dual-registered under the same service name)
Primary use
Unknown — IANA registers only the bare service name, with no expanded description, RFC, or protocol specification published
Other/unofficial uses
possible name-match link to Micom Systems, Inc. (telecom/networking equipment vendor, founded 1975, acquired by Philips NV in 1984) — circumstantial only, no primary source confirms it
Security implications
no CVE or malware association is recorded as of an August 2026 search; no documented protocol or corroborated deployment exists, so an open port should be investigated rather than assumed benign
Typically seen on
Unknown — no corroborated sightings from vendor docs, blogs, or forums were found
- Analyst note
- A registered but essentially undocumented port with negligible measured open-frequency and no confirmed legitimate deployment — treat an open 490/udp as worth investigating rather than expected traffic.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| micom-pfs | UDP | — | 0.06% |
| micom-pfs | TCP | — | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.