Vulnerability scanners may flag SEPM's HTTP port 9090 as an "unencrypted administrative interface", since it responds over plain HTTP.
Port 9090 does not serve the SEPM administrative console, and no login, session, or administrative traffic ever travels over it. It serves a single static landing page whose only two functions are:
No credentials are entered, no session is established, and no confidential or customer data is transmitted or displayed on this page. The actual console, where authentication, session cookies, and administrative actions occur is served exclusively over HTTPS on port 8443.
If your organization requires port 9090 to be closed, this article outlines the steps to disable it.
Symantec Endpoint Protection Manager 14.x
Disabling port 9090 will remove access to its landing page and the easy certificate download link. Before proceeding, download the SEPM server's SSL certificate from the 9090 landing page and distribute it to any admin workstations that need to trust the HTTPS console.
Disabling port 9090 will break the Start Menu shortcut for the web console. To resolve this perform the following steps: