Port 502Modbus Protocol
Port 502 is primarily associated with Modbus, a widely used industrial automation protocol. It facilitates communication between supervisory computers, controllers, and field devices like PLCs over TCP/IP networks..
- transport
- tcp · udp
- in transit
- cleartext
- assignment
- unofficial
- risk
- 4/10
- lookups
- 19,239
2 transports registered
payload readable on path
used by convention
caution
rank 134 of 993 · top 13%
1 other service is registered on port 502. compare all 2 →
Technical Details
what runs on :502Modbus is a communication protocol originally developed by Modicon in 1979 for use with programmable logic controllers (PLCs). It enables client-server communication between devices on industrial networks, allowing for monitoring and control of automation equipment. Modbus over TCP/IP (commonly referred to as Modbus TCP) standardizes this communication on modern Ethernet networks and predominantly uses port 502.
Port 502 serves as the default listening port for Modbus TCP servers (slaves). The protocol supports simple request-response messaging, making it straightforward to implement but lacking in complexity. It’s often favored in distributed control systems and SCADA (Supervisory Control and Data Acquisition) environments due to its openness and simplicity.
Besides TCP, Modbus can also operate over UDP for applications requiring lower overhead or less reliability, though TCP remains more prevalent. The protocol does not inherently support encryption or strong authentication, relying instead on network architecture segmentation and external protections.
Security Information
exposure of :502risk score
4/ 10caution
worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.
network services averages 3.9 across 604 ports — this one sits 0.1 above.
in transit
cleartext
credentials and payloads are readable by anyone on path
assignment
unofficial
used by convention, not registered — what answers here varies by deployment
reachable over
tcp · udp
udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite
security overview
Common Vulnerabilities:
- Lack of authentication, enabling unauthorized commands
- Absence of encryption, exposing transmitted data to interception or tampering
- Susceptibility to Man-in-the-Middle attacks
- Protocol manipulation, leading to denial of service or device malfunction
Common Mitigations:
- Segmenting industrial networks from enterprise or public networks via firewalls
- Using VPNs or secure tunnels to encrypt communications
- Applying strict network access control through ACLs
- Deploying intrusion detection specific to industrial protocols (IDS/IPS)
- Keeping devices and firmware up to date to address known vulnerabilities
Related Ports
the 8 most looked-up other ports in network services — 604 ports carry that label.
| port | service | risk | |||
|---|---|---|---|---|---|
| :9080 | Groove RPC | TCPUDP | Web Services | caution | 70.8k |
| :6543 | Jetnet | UDP | Network Services | caution | 65.3k |
| :5938 | TeamViewer | TCPUDP | Remote Access | caution | 65.0k |
| :8291 | Winbox MikroTik Admin | TCP | Security | caution | 62.9k |
| :3233 | WhiskerControl Protocol | TCPUDP | Network Services | caution | 61.9k |
| :3268 | Microsoft Global Catalog (GC) | TCPUDP | Security | caution | 54.6k |
| :135 | Microsoft EPMAP | TCPUDP | Security | caution | 51.9k |
| :3128 | Tatsoft Default HTTP Proxy | TCP | Web Services | caution | 46.8k |
risk mix of the 8 listed
- caution100%
0 of 8 encrypted