Port 502: Modbus Application Protocol over TCP
TCP 502 is the registered port for Modbus/TCP, which the Modbus organization describes as widely deployed in industrial control systems, for example between HMI or SCADA applications and devices. The Modbus messaging implementation guide states that all Modbus/TCP ADUs are sent via TCP to port 502. A TLS-based variant, Modbus/TCP Security, uses port 802.
Port Details
Security Exposure
Plain Modbus/TCP lacks the protections that Modbus/TCP Security adds through TLS: confidentiality, integrity, anti-replay protection, and certificate-based endpoint authentication. The Modbus messaging guide treats access control as an optional module, so a device without it can answer any host that reaches port 502. CISA, FBI, EPA and DOE warn that OT devices connected to the internet are easy targets, lack authentication resistant to modern threats, and are found by searching for open ports on public IP ranges.
Hardening
- +Remove Modbus devices from the public internet and place them behind an OT firewall or DMZ.
- +Allow port 502 only from the specific HMI and SCADA hosts that need it.
- +Use Modbus/TCP Security on port 802 where devices support it, for TLS and certificate-based authentication.
- +Require VPN with phishing-resistant MFA for any remote access to OT networks.
- +Change default passwords on PLC programming and management interfaces.
Monitoring
Monitor OT network traffic for Modbus write function codes from hosts other than approved HMIs or engineering workstations. Alert on any Modbus traffic crossing the IT/OT boundary.
Tools for Auditing and Monitoring Modbus/TCP
Conpot
Open SourceLow-interaction ICS/SCADA honeypot simulating industrial controllers and protocols.
Dragos
CommercialOT cybersecurity platform for asset visibility, vulnerability prioritization, and ICS threat detection.
Claroty
CommercialCPS protection platform spanning OT, IoT, and medical devices with monitoring, access, and exposure modules.
Related Tool Categories
Frequently Asked Questions
Does Modbus TCP have authentication?→
Traditional Modbus/TCP on port 502 has no authentication. The Modbus/TCP Security protocol on port 802 adds TLS with X.509v3 certificates for client and server authentication.
Should port 502 be reachable from the internet?→
No. CISA and partner agencies list removing OT connections from the public internet as a primary mitigation.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 502 is not guaranteed to be Modbus/TCP. Exploited-in-the-wild data from the CISA KEV catalog (CC0).