Over 4,400 Rockwell PLCs Exposed Online, 22 in Water Attack Cities

Recent analyses have revealed that over 4,400 Rockwell Automation programmable logic controllers (PLCs) are accessible online, with 22 located in cities that have experienced cyberattacks on water utilities. Notably, 19 of these 22 controllers operate on the same mobile carrier network.

A scan conducted on August 3 identified 4,407 exposed Rockwell controllers worldwide, including 2,844 in the United States. While there is no confirmation that these controllers have been compromised, their exposure presents significant security risks. The number reflects exposed controllers rather than the number of affected water utilities or confirmed victims.

Attackers have been able to alter IP addresses and set passwords on these internet-facing controllers without exploiting specific vulnerabilities. Such actions have led to operators losing visibility and, in some cases, control over connected equipment. The methods used by attackers to locate, select, or initially access these targets remain unclear.

Since July 27, water and wastewater utilities in at least seven states have reported incidents, according to a public service announcement by the FBI and EPA. The exact number of affected states varies between reports, but the consensus underscores the urgency of addressing these vulnerabilities.

To mitigate these risks, it is imperative to remove these controllers from public internet exposure. Exposing EtherNet/IP on port 44818 provides an unauthenticated pathway that allows attackers to identify or modify controller settings, depending on device configuration.

Over 70% of the exposed controllers in the U.S. are found on major mobile carrier networks. The FBI and EPA recommend implementing strong authentication measures, regular updates, and comprehensive logging for cellular modems. Additionally, remote access should be isolated through private APNs, VPNs, or similar architectures.

A snapshot from July 30 identified 4,148 exposed Rockwell/Allen-Bradley EtherNet/IP hosts, with Verizon Business, AT&T Mobility, and T-Mobile USA accounting for 59% of these exposures. While figures from different platforms and dates may vary, the consistent identification of over 4,100 exposed hosts highlights the scale of the issue.

MicroLogix 1400 devices constitute 50% of the exposed controllers, with MicroLogix 1100 devices making up 8%. Notably, 19 of the 22 controllers in affected cities are running firmware susceptible to CVE-2017-16740, a Modbus TCP buffer overflow vulnerability affecting certain MicroLogix 1400 Series B and C devices. Rockwell addressed this issue in firmware revision 21.003. However, merely updating firmware does not justify exposing PLCs directly to the public internet.

Rockwell discontinued the MicroLogix 1100 on April 30, 2022. Advisory SD1790 provides guidance for operators who have been locked out due to attacker-set passwords, detailing steps to reset affected devices to factory defaults and reload known-good project files. This recovery process necessitates having an up-to-date offline copy of the controller logic.

The exposure of these PLCs underscores the critical need for robust cybersecurity measures in industrial control systems. Organizations must prioritize securing their infrastructure by removing critical devices from public internet access, implementing strong authentication protocols, and ensuring regular firmware updates. The recent incidents serve as a stark reminder of the vulnerabilities inherent in connected industrial systems and the potential consequences of neglecting cybersecurity best practices.