A vendor claims their Modbus TCP gateway is secure because the master must send the correct unit ID in every request. What is the flaw in that claim?
- A.Unit ID is a routing field with no secret or identity check
- B.Unit ID is validated against a certificate held on the client
- C.Unit ID is hashed by the gateway before each request
- D.Unit ID is rotated by the master near the end of each poll cycle
Why A is correct
The unit ID only selects a target device behind the gateway, such as a serial slave address. It carries no secret, signature, or certificate, so anyone who can reach the gateway can guess it.
Know someone studying for OT Security Fundamentals? Send them this one.