A new Forescout scan found more than 4,000 Rockwell Automation and Allen-Bradley controllers exposed on the internet, with 22 still visible in cities affected by recent attacks on U.S. water systems. The research highlights ongoing risks from public-facing EtherNet/IP devices, stale remote-access services, and possible exposure to CVE-2017-16740 on some MicroLogix 1400 systems. #RockwellAutomation #AllenBradley #MicroLogix1400 #CVE-2017-16740
Keypoints
- Forescout found over 4,000 Rockwell Automation and Allen-Bradley controllers exposed online.
- Most exposed devices were located in the United States.
- The controllers used EtherNet/IP, which can allow remote identification and configuration changes when exposed.
- Twenty-two exposed devices were found in cities impacted by recent water system attacks.
- Some exposed hosts may be vulnerable to CVE-2017-16740 if Modbus TCP is enabled.
Read More: https://cyberscoop.com/exposed-rockwell-controllers-water-system-attacks/