Port 502Modbus Protocol

Port 502 is primarily associated with Modbus, a widely used industrial automation protocol. It facilitates communication between supervisory computers, controllers, and field devices like PLCs over TCP/IP networks..

transport
tcp · udp

2 transports registered

in transit
cleartext

payload readable on path

assignment
unofficial

used by convention

risk
4/10

caution

lookups
19,239

rank 134 of 993 · top 13%

1 other service is registered on port 502. compare all 2

Technical Details

what runs on :502

Modbus is a communication protocol originally developed by Modicon in 1979 for use with programmable logic controllers (PLCs). It enables client-server communication between devices on industrial networks, allowing for monitoring and control of automation equipment. Modbus over TCP/IP (commonly referred to as Modbus TCP) standardizes this communication on modern Ethernet networks and predominantly uses port 502.

Port 502 serves as the default listening port for Modbus TCP servers (slaves). The protocol supports simple request-response messaging, making it straightforward to implement but lacking in complexity. It’s often favored in distributed control systems and SCADA (Supervisory Control and Data Acquisition) environments due to its openness and simplicity.

Besides TCP, Modbus can also operate over UDP for applications requiring lower overhead or less reliability, though TCP remains more prevalent. The protocol does not inherently support encryption or strong authentication, relying instead on network architecture segmentation and external protections.

Security Information

exposure of :502

risk score

4/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

network services averages 3.9 across 604 ports — this one sits 0.1 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

unofficial

used by convention, not registered — what answers here varies by deployment

reachable over

tcp · udp

udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite

security overview

Common Vulnerabilities:

  • Lack of authentication, enabling unauthorized commands
  • Absence of encryption, exposing transmitted data to interception or tampering
  • Susceptibility to Man-in-the-Middle attacks
  • Protocol manipulation, leading to denial of service or device malfunction

Common Mitigations:

  • Segmenting industrial networks from enterprise or public networks via firewalls
  • Using VPNs or secure tunnels to encrypt communications
  • Applying strict network access control through ACLs
  • Deploying intrusion detection specific to industrial protocols (IDS/IPS)
  • Keeping devices and firmware up to date to address known vulnerabilities

the 8 most looked-up other ports in network services — 604 ports carry that label.

risk mix of the 8 listed

  • caution100%

0 of 8 encrypted