Modbus exception codes

What each exception response means, what usually causes it, and how to tell an exception apart from a timeout.

5 min read · Updated

When a device understands your request but will not answer it, it returns an exception. That is good news: the device is alive, the framing is right, and the problem is in what you asked for. A timeout tells you much less.

How an exception looks on the wire

The device echoes your function code with the high bit set, then one byte of exception code. A failed FC03 comes back as 0x83 followed by the code.

Request and exception response
request   01 03 00 64 00 02      read 2 holding registers from address 100
response  01 83 02               exception 02: illegal data address

The codes you will actually see

CodeNameWhat it usually means
01Illegal functionThe device does not implement this function code. Reading input registers from a device that only has holding registers gives this.
02Illegal data addressThe address, or the address plus the quantity, is outside what the device maps. The most common exception by far.
03Illegal data valueThe quantity is out of range — asking for 0 registers, or more than 125 in one read.
04Server device failureThe device hit an internal error trying to serve the request.
05AcknowledgeThe request was accepted but will take a while. Rare in reads.
06Server device busyThe device is occupied. Retry after a pause.
0BGateway target device failed to respondA Modbus gateway could not reach the downstream device — the unit ID is wrong, or the serial device is off.

Exception 02 is usually one of four things

  1. Off-by-one from the 4xxxx convention — you asked for 40100 instead of protocol address 99.
  2. The wrong table — the value is in input registers and you used FC03.
  3. A read that starts inside a valid block but runs past its end, because the quantity is too large.
  4. A gap in the device's map. Many devices map scattered blocks, not a continuous range.
A block read that fails with exception 02 does not mean every register in it is missing. Splitting the block and re-reading the halves finds the boundary, which is how an adaptive scan narrows down a real map.

Exception versus timeout

An exception is an answer. A timeout is silence, and the causes are different: wrong IP or port, wrong unit ID on a serial line, wrong baud rate or parity, a cable, or a device that is simply off. If some unit IDs answer and others time out on the same line, the line is fine and the unit ID is wrong.

Never treat a timeout as a zero. A value that could not be read is not a value; passing it downstream as 0 has caused more than one spurious alarm.
Free tool

Modbus Polling Tool

Poll, inspect and troubleshoot Modbus devices in real time.

Modbus exception codes | Modbus Logic