Skip to content
Zyberum Cyber Security Firm
Menu
GlossaryOTProtocols

Modbus

Modbus is the simplest and most widespread industrial protocol: RTU over serial lines, TCP on port 502. How it works, why it has no security and how to protect it anyway.

Updated This page as Markdown

In short

Modbus is an open, royalty-free industrial communication protocol from 1979, maintained by the Modbus Organization. A client reads and writes coils and registers on a server using numbered function codes, over serial lines (Modbus RTU) or TCP port 502 (Modbus TCP). The protocol has no authentication, integrity protection or encryption: anyone who can reach the port can read and write process values. Modbus/TCP Security adds TLS on port 802 but is rarely implemented in devices.

What is Modbus?

Modbus is an application-layer protocol for industrial devices, published by Modicon in 1979 and maintained today by the Modbus Organization as an open, royalty-free specification. Its simplicity made it the most widely implemented industrial protocol: nearly every PLC, drive, meter, sensor gateway and HMI speaks it.

The model is client/server (historically master/slave). The client sends a request with a function code and an address, the server answers with data or an exception. The data model has four tables: coils (single bits, read/write), discrete inputs (single bits, read-only), input registers (16-bit, read-only) and holding registers (16-bit, read/write). The common function codes are 01 to 04 for reading, 05 and 06 for writing a single coil or register, 15 and 16 for writing several, 08 for diagnostics and 43 for reading device identification.

Modbus RTU runs over RS-485 or RS-232 serial lines with a CRC; Modbus ASCII is its text variant. Modbus TCP wraps the same protocol data unit in an MBAP header and sends it over TCP port 502. Gateways translate between the variants, which is how serial devices from the 1990s end up reachable over IP.

Where is it defined?

The Modbus Organization publishes the Modbus Application Protocol Specification (V1.1b3), the Modbus Messaging on TCP/IP Implementation Guide, the Modbus over Serial Line Specification and, since 2018, the Modbus/TCP Security Protocol Specification, which adds TLS on port 802 with certificate-based authentication and role information. All are free downloads. The system-level requirements that Modbus cannot meet on its own, such as authentication and integrity of control traffic, are stated in IEC 62443-3-3 and are the reason compensating controls are needed around it.

What it means in practice

Modbus is the clearest example of an industrial protocol designed for a trusted wire. Typical findings:

  • Reachable from the wrong network. Port 502 is open from the office VLAN, from the vendor VPN or, through a cellular gateway, from the internet. Reading registers from there is trivial; writing is one function code away.
  • Writes unrestricted. No device distinguishes who may write. A firewall that allows “Modbus” allows function codes 05, 06, 15 and 16 as well, unless it inspects the protocol.
  • Fragile stacks. Malformed frames or high request rates stop devices or trigger resets. We have seen this on PLCs, energy meters and protocol gateways alike.
  • Gateways as blind spots. Serial-to-TCP gateways expose dozens of field devices through one IP address, often with a web interface and default credentials.
  • No monitoring. Nobody records which host wrote which register; after an incident the historian shows the effect but not the cause.

The protective pattern is well understood: put Modbus devices in their own zone, allow only the HMI and SCADA server through a conduit, use a Modbus-aware firewall or data diode that permits read function codes and only the specific writes the process needs, enable hardware write-protection switches where devices have them, and run passive monitoring that alerts on writes from new sources. During a test we enumerate devices with function code 43 and read-only requests, never write to a live process, and move protocol fuzzing to bench units.

Common misunderstandings

Modbus is not “only serial” and therefore unreachable; Modbus TCP and gateways made it an IP protocol decades ago. A closed port 502 on the firewall does not mean no Modbus is exposed; the gateway on the cellular router is the usual exception. And Modbus/TCP Security is not a configuration switch on existing devices: it needs new firmware, certificates and a plan for managing them.

FAQ

Frequently asked questions

Is Modbus secure?

Classic Modbus is not: there is no authentication, no integrity check beyond the serial CRC and no encryption. Any host that can reach TCP port 502 can read every register and write every coil. Security has to come from the network around it: segmentation, a protocol-aware firewall that permits only the function codes and unit IDs the HMI needs, and monitoring for writes from unexpected sources.

What does Modbus/TCP Security change?

The Modbus Organization published Modbus/TCP Security in 2018. It wraps Modbus TCP in TLS on port 802 with mutual certificate authentication and role-based authorisation carried in the certificate. It solves the protocol problem on paper, but it needs device support on both ends and a certificate infrastructure in the plant, which is why installed devices almost never use it.

Can a Modbus scan crash a device?

Yes. Many Modbus stacks in PLCs, gateways and meters handle malformed frames, unexpected function codes or high request rates badly and stop responding or reset. That is why we enumerate devices read-only and at low rates in running plants, and fuzz the protocol stack only on bench units with the manufacturer.

Sources

Related pages

Get started

A term that applies to your product?

In 15 minutes we tell you what it means for you in practice, which requirement follows from it and what the sensible next step is.

  • Direct answer from a security engineer
  • Which standard or law applies to you
  • Free and without obligation
Tom Zaubermann

Your call is withTom ZaubermannFounder & CEO, Zyberum

Call us: +49 176 439 17074info@zyberum.com

Or send us a message

We reply within one business day.

Call usAsk a security engineer

Pick a time that suits you

Open in a new tab