Protect.Computer
NEWS

4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities

· 1 min read · Network safety
4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities

Security researchers at Forescout scanned the public internet in early August and found 4,407 Rockwell Automation programmable logic controllers (PLCs) directly reachable on port 44818 — the standard EtherNet/IP management port — with no firewall or authentication wall in front of them. Of the 2,844 exposed units in the United States, 22 were located in cities that have already experienced confirmed cyberattacks targeting their water or wastewater systems. An attacker who can reach one of these controllers can query device configuration and, on vulnerable firmware, overwrite settings that govern physical processes like chemical dosing or pump control.

The most exposed model is the MicroLogix 1400 (roughly half of all findings), followed by the MicroLogix 1100. Both are affected by CVE-2017-16740, a Modbus TCP buffer overflow in MicroLogix 1400 Series B and C devices running firmware version 21.002 and earlier, with a CVSS score of 8.6. The vulnerability is nearly a decade old and was patched by Rockwell in 2017, but Forescout’s scan shows most exposed units are still running vulnerable firmware. The FBI and EPA issued a joint public service announcement on July 30 urging water utilities to isolate OT networks, require strong authentication on remote-access paths, and audit any internet-facing industrial equipment.

How to check if you’re affected

Affected products are Rockwell Automation MicroLogix 1400 Series B/C running firmware versions before 21.003, and MicroLogix 1100 devices with EtherNet/IP enabled. Water and wastewater operators should immediately audit whether any MicroLogix PLC is directly reachable from the internet on TCP port 44818. Patch to firmware 21.003 or later to remediate CVE-2017-16740; if patching is not immediately possible, block port 44818 at the network perimeter and restrict access to a dedicated OT VLAN with no public routing.

Sources

Related reading