62
Summary
- // if you see it open
- Low inherent risk: no known active implementation or exploit targets the port. SANS Internet Storm Center records only sporadic low-level probes, no CVEs tied to the port, and no elevated threat designation (threat status green, June 2026). Because no legitimate service is known to use it, an open 62/tcp on a public host is anomalous and should be investigated as a possible misconfiguration or unauthorized service.
- // analyst note
- No recognizable application signature exists for this port; treat a listening 62/tcp as a reconnaissance flag and investigate rather than assume a benign service.
About port 62/tcp.
Port 62/tcp is registered with IANA as acas with the description "ACA Services," assignee and contact both listed as [E_Wald], and a blank reference field; it is dual-registered on TCP and UDP. Unlike the well-known small-services or login ports, the underlying ACA Services protocol is effectively undocumented in public sources — there is no cited RFC in the registry, no widely-available specification, and no known open-source or commercial software that binds port 62 for its registered purpose today. The IANA reference column is blank, so no standards document is recorded. Analysts should note an important name collision: "ACAS" also refers to the U.S. Department of Defense Assured Compliance Assessment Solution, a Tenable-based vulnerability-scanning program, but that product is unrelated to this registration and does not use port 62 — the shared acronym is coincidental. From a monitoring standpoint, SANS Internet Storm Center records only low-level, sporadic probe activity against port 62 with no CVEs tied to the port and no elevated threat designation as of June 2026 (ISC threat status green). Because no active legitimate service is known to use the port, any host found listening on 62/tcp on a public interface is anomalous and worth investigating as a possible misconfiguration or unauthorized service rather than an expected daemon. The inherent risk from the registered service itself is low — there are simply no documented implementations or exploits to target — but the rarity of legitimate use is precisely what makes an open instance noteworthy. Treat a responsive port 62 as a reconnaissance flag rather than a recognizable application signature.
- IANA assignment
acas— "ACA Services"; reference (blank — no RFC cited in IANA registry); assignee/contact[E_Wald]; dual-registered 62/tcp + 62/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (the IANA Service Name and Transport Protocol Port Number Registry rows 132-133)- Range class
- well-known (0–1023)
- Registration / modification dates
- blank in the IANA registry — recorded as null, not fabricated [Confirmed] — IANA registry
- Related ports
- other low-documentation well-known assignments in the same block
Primary use
registered as "ACA Services" but the protocol is publicly undocumented — no RFC, no known active implementation
Other/unofficial uses
none documented; name collision with the DoD "ACAS" (Assured Compliance Assessment Solution) is coincidental and unrelated — that tool does not use port 62
Common software
Unknown — no widely-used product is known to bind 62/tcp for its registered purpose
Security implications
low inherent risk (no known active implementation or exploit); SANS ISC shows only sporadic low-level probes, no CVEs, threat status green (June 2026); an open 62/tcp on a public host is anomalous and worth investigating
Typically seen on
nothing in particular; a responsive port 62 is an anomaly / possible misconfiguration or unauthorized service
- Analyst note
- No recognizable application signature exists for this port; treat a listening 62/tcp as a reconnaissance flag and investigate rather than assume a benign service.
About port 62/udp.
Port 62/udp is registered with IANA under the service name acas, description "ACA Services," assignee E. Wald, with a blank reference field. The registration is dual: port 62 is allocated for both TCP and UDP with identical metadata (acas / "ACA Services" / assignee E. Wald) in the IANA Service Name and Transport Protocol Port Number Registry. No RFC or standards document governs the service — the IANA reference column is blank, and no registration or modification date is recorded in the registry, so those fields stay null rather than being invented. "ACA Services" is a legacy early-internet allocation with no publicly documented protocol specification and no known active software, product, or implementation associated with it today; the assignment appears effectively dormant. For an analyst, that absence is the operative fact: port 62 sits in the well-known range (0–1023) but carries no expected legitimate UDP traffic, so unexpected inbound datagrams on 62/udp are anomalous and a reasonable default-block at the perimeter. Third-party port databases (AuditMyPC, SpeedGuide) note historical malicious-actor interest around port 62, with the malware lore concentrated on the TCP side; no CVE or specifically named malware tied to 62/udp surfaced in this research pass, and UDP scan visibility is inherently lower than TCP, so internet-wide exposure for 62/udp is not separately well documented. Treat a responsive 62/udp as worth investigating rather than as a recognized service.
- IANA assignment
acas— "ACA Services"; reference (blank — no RFC cited in IANA registry); assignee E. Wald; dual-registered 62/tcp + 62/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (the IANA Service Name and Transport Protocol Port Number Registry)- Range class
- well-known (0–1023) [Confirmed]
- Registration / modification date
- none recorded in registry — stays null (not fabricated) [Confirmed] — IANA CSV (blank columns)
- Related ports
- 62/tcp (identical IANA registration)
Primary use
IANA-registered "ACA Services"; legacy early-internet allocation, no RFC and no publicly documented protocol spec; no known active software using it today
Common software
none identified — no documented implementation of "ACA Services" on 62/udp found [Unknown]
Security implications
third-party DBs note historical malicious-actor interest (malware lore concentrated on 62/tcp); no CVE or named malware tied to 62/udp found this pass; well-known port with no legitimate active responder, so unexpected inbound is suspicious — reasonable default-block
Exposure / scanning
no specific Shodan/Censys data for 62/udp found this pass; UDP scan visibility inherently lower than TCP [Unknown]
- Analyst note
- A responsive 62/udp is statistically unusual with no known legitimate service behind it — investigate rather than assume a benign listener.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| acas | UDP | ACA Services | 0.03% |
| acas | TCP | ACA Services | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.