Skip to main content

Port Details

Port
502
Transport
TCP
Service
Modbus/TCP
IANA service name
mbap
Range
System port (0-1023)
Related ports
802

Security Exposure

Plain Modbus/TCP lacks the protections that Modbus/TCP Security adds through TLS: confidentiality, integrity, anti-replay protection, and certificate-based endpoint authentication. The Modbus messaging guide treats access control as an optional module, so a device without it can answer any host that reaches port 502. CISA, FBI, EPA and DOE warn that OT devices connected to the internet are easy targets, lack authentication resistant to modern threats, and are found by searching for open ports on public IP ranges.

Hardening

  • +Remove Modbus devices from the public internet and place them behind an OT firewall or DMZ.
  • +Allow port 502 only from the specific HMI and SCADA hosts that need it.
  • +Use Modbus/TCP Security on port 802 where devices support it, for TLS and certificate-based authentication.
  • +Require VPN with phishing-resistant MFA for any remote access to OT networks.
  • +Change default passwords on PLC programming and management interfaces.

Monitoring

Monitor OT network traffic for Modbus write function codes from hosts other than approved HMIs or engineering workstations. Alert on any Modbus traffic crossing the IT/OT boundary.

Tools for Auditing and Monitoring Modbus/TCP

Conpot

Open Source
Honeypot & Deception Tools

Low-interaction ICS/SCADA honeypot simulating industrial controllers and protocols.

LicenseGPL-2.0-or-later
PlatformLinux

Dragos

Commercial
OT/ICS Security Tools

OT cybersecurity platform for asset visibility, vulnerability prioritization, and ICS threat detection.

LicenseProprietary
PlatformWeb, Hardware

Claroty

Commercial
OT/ICS Security Tools

CPS protection platform spanning OT, IoT, and medical devices with monitoring, access, and exposure modules.

LicenseProprietary
PlatformWeb

Frequently Asked Questions

Does Modbus TCP have authentication?→

Traditional Modbus/TCP on port 502 has no authentication. The Modbus/TCP Security protocol on port 802 adds TLS with X.509v3 certificates for client and server authentication.

Should port 502 be reachable from the internet?→

No. CISA and partner agencies list removing OT connections from the public internet as a primary mitigation.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 502 is not guaranteed to be Modbus/TCP. Exploited-in-the-wild data from the CISA KEV catalog (CC0).