Modbus
Modbus is the simplest and most widespread industrial protocol: RTU over serial lines, TCP on port 502. How it works, why it has no security and how to protect it anyway.
Updated This page as Markdown
In short
Modbus is an open, royalty-free industrial communication protocol from 1979, maintained by the Modbus Organization. A client reads and writes coils and registers on a server using numbered function codes, over serial lines (Modbus RTU) or TCP port 502 (Modbus TCP). The protocol has no authentication, integrity protection or encryption: anyone who can reach the port can read and write process values. Modbus/TCP Security adds TLS on port 802 but is rarely implemented in devices.
What is Modbus?
Modbus is an application-layer protocol for industrial devices, published by Modicon in 1979 and maintained today by the Modbus Organization as an open, royalty-free specification. Its simplicity made it the most widely implemented industrial protocol: nearly every PLC, drive, meter, sensor gateway and HMI speaks it.
The model is client/server (historically master/slave). The client sends a request with a function code and an address, the server answers with data or an exception. The data model has four tables: coils (single bits, read/write), discrete inputs (single bits, read-only), input registers (16-bit, read-only) and holding registers (16-bit, read/write). The common function codes are 01 to 04 for reading, 05 and 06 for writing a single coil or register, 15 and 16 for writing several, 08 for diagnostics and 43 for reading device identification.
Modbus RTU runs over RS-485 or RS-232 serial lines with a CRC; Modbus ASCII is its text variant. Modbus TCP wraps the same protocol data unit in an MBAP header and sends it over TCP port 502. Gateways translate between the variants, which is how serial devices from the 1990s end up reachable over IP.
Where is it defined?
The Modbus Organization publishes the Modbus Application Protocol Specification (V1.1b3), the Modbus Messaging on TCP/IP Implementation Guide, the Modbus over Serial Line Specification and, since 2018, the Modbus/TCP Security Protocol Specification, which adds TLS on port 802 with certificate-based authentication and role information. All are free downloads. The system-level requirements that Modbus cannot meet on its own, such as authentication and integrity of control traffic, are stated in IEC 62443-3-3 and are the reason compensating controls are needed around it.
What it means in practice
Modbus is the clearest example of an industrial protocol designed for a trusted wire. Typical findings:
- Reachable from the wrong network. Port 502 is open from the office VLAN, from the vendor VPN or, through a cellular gateway, from the internet. Reading registers from there is trivial; writing is one function code away.
- Writes unrestricted. No device distinguishes who may write. A firewall that allows “Modbus” allows function codes 05, 06, 15 and 16 as well, unless it inspects the protocol.
- Fragile stacks. Malformed frames or high request rates stop devices or trigger resets. We have seen this on PLCs, energy meters and protocol gateways alike.
- Gateways as blind spots. Serial-to-TCP gateways expose dozens of field devices through one IP address, often with a web interface and default credentials.
- No monitoring. Nobody records which host wrote which register; after an incident the historian shows the effect but not the cause.
The protective pattern is well understood: put Modbus devices in their own zone, allow only the HMI and SCADA server through a conduit, use a Modbus-aware firewall or data diode that permits read function codes and only the specific writes the process needs, enable hardware write-protection switches where devices have them, and run passive monitoring that alerts on writes from new sources. During a test we enumerate devices with function code 43 and read-only requests, never write to a live process, and move protocol fuzzing to bench units.
Common misunderstandings
Modbus is not “only serial” and therefore unreachable; Modbus TCP and gateways made it an IP protocol decades ago. A closed port 502 on the firewall does not mean no Modbus is exposed; the gateway on the cellular router is the usual exception. And Modbus/TCP Security is not a configuration switch on existing devices: it needs new firmware, certificates and a plan for managing them.
FAQ
Frequently asked questions
Is Modbus secure?
Classic Modbus is not: there is no authentication, no integrity check beyond the serial CRC and no encryption. Any host that can reach TCP port 502 can read every register and write every coil. Security has to come from the network around it: segmentation, a protocol-aware firewall that permits only the function codes and unit IDs the HMI needs, and monitoring for writes from unexpected sources.
What does Modbus/TCP Security change?
The Modbus Organization published Modbus/TCP Security in 2018. It wraps Modbus TCP in TLS on port 802 with mutual certificate authentication and role-based authorisation carried in the certificate. It solves the protocol problem on paper, but it needs device support on both ends and a certificate infrastructure in the plant, which is why installed devices almost never use it.
Can a Modbus scan crash a device?
Yes. Many Modbus stacks in PLCs, gateways and meters handle malformed frames, unexpected function codes or high request rates badly and stop responding or reset. That is why we enumerate devices read-only and at low rates in running plants, and fuzz the protocol stack only on bench units with the manufacturer.
Sources
Related pages
- GlossaryPLC (Programmable Logic Controller)A PLC is the industrial computer that runs the control logic of a machine or process. How PLCs work, which standards apply and where their security typically fails.
- GlossaryOPC UAOPC UA (IEC 62541) is the platform-independent industrial communication standard with built-in security. Security policies, certificates and the misconfigurations we see.
- GlossarySCADASCADA systems supervise and control distributed processes such as power grids, water networks and pipelines. Architecture, protocols and the security issues they bring.
- GlossaryZones and conduitsZones and conduits are the IEC 62443 model for segmenting industrial systems: groups of assets with common security requirements and the controlled links between them.
- InsightsOT Penetration Testing Without Downtime: How It Is DoneHow to test a plant without stopping production: passive analysis, test benches and twins, what belongs in a maintenance window, what is never done on a live plant.
- ServicesKeep production running when IT and OT converge.Security assessments, pentests and IEC 62443 consulting for PLC, SCADA and DCS. Protect production and critical infrastructure against cyberattacks.
