Despite federal warnings, thousands of U.S. industrial controllers used in water systems remain exposed online

Despite federal warnings, thousands of U.S. industrial controllers used in water systems remain exposed online
A new Forescout scan found more than 4,000 Rockwell Automation and Allen-Bradley controllers exposed on the internet, with 22 still visible in cities affected by recent attacks on U.S. water systems. The research highlights ongoing risks from public-facing EtherNet/IP devices, stale remote-access services, and possible exposure to CVE-2017-16740 on some MicroLogix 1400 systems. #RockwellAutomation #AllenBradley #MicroLogix1400 #CVE-2017-16740

Keypoints

  • Forescout found over 4,000 Rockwell Automation and Allen-Bradley controllers exposed online.
  • Most exposed devices were located in the United States.
  • The controllers used EtherNet/IP, which can allow remote identification and configuration changes when exposed.
  • Twenty-two exposed devices were found in cities impacted by recent water system attacks.
  • Some exposed hosts may be vulnerable to CVE-2017-16740 if Modbus TCP is enabled.

Read More: https://cyberscoop.com/exposed-rockwell-controllers-water-system-attacks/