A digital representation of a Rockwell PLC connected to a vulnerable network, highlighting cybersecurity risks to industrial control systems.
Uncategorized

Cyber Alarms Ring: Thousands of Industrial PLCs Exposed Online, Water Utilities at Risk

Share
Share

A stark warning has been issued to critical infrastructure operators: thousands of Rockwell Automation Programmable Logic Controllers (PLCs), vital components in industrial control systems, are directly exposed to the internet. This alarming discovery comes amidst a wave of cyberattacks targeting U.S. water utilities, raising serious concerns about the nation’s operational technology (OT) security posture.

The Alarming Scale of Exposure

Cybersecurity firm Forescout’s recent scan revealed a staggering 4,407 internet-facing Rockwell controllers worldwide as of August 3, with 2,844 located within the United States. More critically, 22 of these exposed PLCs were identified in cities that have recently experienced cyberattacks on their water utilities. A concerning 19 of these 22 devices were even found operating on the same mobile carrier network, suggesting potential patterns in attacker targeting or common deployment vulnerabilities.

While Forescout could not confirm direct compromises of these specific devices, the sheer accessibility presents an undeniable risk. Another snapshot by Censys on July 30 corroborated the scale of the problem, identifying 4,148 exposed Rockwell/Allen-Bradley EtherNet/IP hosts, with major mobile carriers like Verizon Business, AT&T Mobility, and T-Mobile USA accounting for 59% of these connections.

Understanding the Attack Vector

The recent cyber incidents affecting water and wastewater utilities across at least seven U.S. states (with some reports suggesting up to 12) highlight a critical vulnerability. Forescout’s analysis indicates that attackers didn’t necessarily exploit complex software flaws to gain access. Instead, they leveraged the direct internet exposure to change IP addresses and set new passwords on already reachable controllers. This simple yet effective tactic led to operators losing visibility and, in some cases, control over their connected equipment.

Common Vulnerable Devices and Flaws

Among the exposed devices, Rockwell’s MicroLogix 1400 and MicroLogix 1100 families are prominent, accounting for 50% and 8% of Forescout’s findings, respectively. Both families were specifically named in government alerts. Furthermore, 19 of the 22 controllers found in affected cities were susceptible to CVE-2017-16740, a Modbus TCP buffer overflow vulnerability (CVSS score: 8.6) affecting MicroLogix 1400 Series B and C running older firmware. While Rockwell released a fix (revision 21.003) years ago, the continued exposure of unpatched systems underscores a significant challenge in OT security.

It’s crucial to note that direct public exposure of PLCs is inherently risky, regardless of specific firmware vulnerabilities. Exposing EtherNet/IP on port 44818 creates an unauthenticated pathway, allowing attackers to identify controllers or even write settings to them, depending on device configuration.

Urgent Call to Action: Securing Critical Infrastructure

The FBI and EPA have issued urgent recommendations for defenders to mitigate these threats. The most immediate and impactful step is to remove industrial controllers from the public internet entirely. For remote access, strong authentication, regular updates, and comprehensive logging for cellular modems are essential. Furthermore, remote access should be strictly isolated through secure architectures like private APNs or VPNs.

Operators of MicroLogix 1400 and 1100 devices, especially those facing password lockouts, can refer to Rockwell Advisory SD1790 for recovery guidance. This involves resetting devices to factory defaults and redownloading a known-good project file – a process that critically depends on having a current, offline backup of the controller logic. The FBI has reported instances where victims discovered modified PLC project files, indicating attackers are not just locking out but potentially altering operational parameters.

The threat extends beyond individual systems; the FBI also warned that similar third-party network setups could enable attackers to replicate successful compromises across multiple customers sharing vulnerable configurations. This highlights the need for a holistic and proactive approach to industrial cybersecurity.

Conclusion

The widespread exposure of Rockwell PLCs online, coupled with recent cyberattacks on water utilities, serves as a critical wake-up call. Protecting these foundational elements of our infrastructure requires immediate action: isolating devices from the public internet, implementing robust security protocols, and maintaining vigilant oversight. The integrity of our essential services depends on it.


For more details, visit our website.

Source: Link

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *