Recent research by Forescout has revealed that 22 Rockwell Automation programmable logic controllers (PLCs) are exposed online in cities that have recently experienced cyberattacks on water utilities. A total of 19 of these controllers are linked via the same mobile carrier network, raising security concerns.
Widespread Vulnerability of Rockwell PLCs
Forescout’s scan on August 3 identified 4,407 Rockwell controllers exposed globally, with 2,844 located in the United States. While these devices are exposed, there is no confirmation of any being compromised. The focus remains on exposed controllers rather than specific water utilities or confirmed victims.
The identified vulnerabilities allow attackers to manipulate these controllers without exploiting specific vulnerabilities. Changes to IP addresses and password settings can disrupt operator control, leading to potential loss of visibility and control over connected systems. However, the exact methods attackers used to identify and target these controllers remain unclear.
Impact on Water Utilities and Suggested Measures
Since July 27, several water utilities across at least seven states have reported incidents, prompting warnings from the FBI and EPA. Conflicting reports from The Hacker News and Forescout suggest the attacks may have affected up to 12 states. Despite this, no official attribution has been made regarding the source of these cyberattacks.
To mitigate risks, experts suggest removing controllers from public internet access. Exposing EtherNet/IP on port 44818 can create an unauthenticated access route, potentially allowing attackers to identify and manipulate controllers. Strong authentication and isolated remote access are recommended by the FBI and EPA to bolster security.
Statistics and Device Vulnerabilities
A snapshot from Censys on July 30 identified 4,148 exposed Rockwell/Allen-Bradley EtherNet/IP hosts, with major mobile carriers accounting for a significant portion of these connections. The different data collection methods between Censys and Forescout make direct comparisons challenging. Historical data shows a significant decline from March 2020 figures, with a June 2026 low of 4,169.
MicroLogix 1400 devices represent a significant portion of the exposed controllers, with 19 of the 22 controllers in affected cities running firmware vulnerable to CVE-2017-16740. Although Rockwell has addressed this buffer overflow flaw in newer firmware versions, public exposure of PLCs remains a critical concern. Recovery paths exist for locked devices, but they rely on having a current offline logic copy.
As these vulnerabilities continue to expose critical infrastructure to potential cyber threats, it is imperative for organizations to enhance their security measures and prevent unauthorized access.
