Port 2404IEC 60870-5-104

IEC 60870-5-104 is a protocol standard widely used for telecontrol in electric power systems, enabling data exchange for supervisory control and data acquisition (SCADA). Operating over TCP/IP networks, it facilitates real-time monitoring and remote management of electrical grids, substations, and automation devices to ensure reliable power delivery..

transport
tcp

single transport

in transit
cleartext

payload readable on path

assignment
official

registered with iana

risk
4/10

caution

lookups
10,529

rank 420 of 993 · top 42%

Technical Details

what runs on :2404

IEC 60870-5-104, commonly referred to as IEC 104, is an international standard protocol designed for telecontrol applications in electric power systems. It extends the IEC 60870-5-101 protocol to TCP/IP-based networks, allowing efficient and reliable communication over Ethernet architecture. This protocol supports the transmission of measurements, events, control commands, and other system information required for the monitoring and management of electrical substations and distribution automation systems.

IEC 104 operates within the framework of a client-server model over a reliable TCP/IP transport layer, which ensures proper sequencing, flow control, and guaranteed delivery. The protocol encapsulates application layer data units (ASDUs), facilitating the exchange of real-time data, control instructions, and critical system status between control centers and various intelligent electronic devices (IEDs). Communication typically occurs continuously in near real-time, allowing immediate response to changes in electrical grid conditions.

Because of its reliance on TCP/IP, IEC 104 is suitable for modern network infrastructures and supports integration with existing IT systems. Its design emphasizes interoperability, vendor-independence, and extensibility, making it a preferred choice for utility companies globally seeking to enhance their automation and telecontrol capabilities within their supervisory control environments.

Security Information

exposure of :2404

risk score

4/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

network services averages 3.9 across 604 ports — this one sits 0.1 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp

every listening transport is another surface to filter at the edge

security overview

Common Vulnerabilities:

  • Lack of built-in encryption or authentication, exposing data to interception or manipulation.
  • Susceptibility to man-in-the-middle (MITM) attacks due to unprotected session establishment.
  • Vulnerability to denial-of-service (DoS) attacks targeting TCP/IP stack resources or protocol-specific message flooding.
  • Potential exploitation through protocol fuzzing to crash implementations or force unpredictable behavior.

Common Mitigations:

  • Encapsulation of IEC 104 traffic in secure tunnels such as VPNs or SSH to protect data confidentiality and integrity.
  • Deployment of network segmentation and strict firewall rules to limit access to telecontrol systems.
  • Implementation of intrusion detection/prevention systems (IDS/IPS) capable of identifying anomalous IEC 104 traffic patterns.
  • Enabling device authentication using certificates or network-based access controls.
  • Regular security assessments, protocol compliance audits, and timely patching of known vulnerabilities in involved hardware and software.

the 8 most looked-up other ports in network services — 604 ports carry that label.

risk mix of the 8 listed

  • caution100%

0 of 8 encrypted