Forescout has identified over 4,400 internet-facing Rockwell Automation programmable logic controllers (PLCs) worldwide, including 22 in cities affected by recent cyberattacks on US water utilities. The August 3 scan found 4,407 exposed controllers, with 2,844 located in the United States. While no compromises were confirmed, the researchers noted that the attacks could have been carried out without exploiting vulnerabilities, as attackers simply changed IP addresses and set passwords on already-reachable devices.
The FBI and EPA have reported incidents at water and wastewater utilities in at least seven states since July 27. Forescout highlighted that exposing EtherNet/IP on port 44818 creates an unauthenticated path that could allow attackers to identify or modify controllers. More than 70% of US-based exposed controllers were found on large mobile carrier networks, with Verizon Business, AT&T Mobility, and T-Mobile USA accounting for 59% of hosts in a separate Censys snapshot.
Among the affected controllers, 19 of the 22 in impacted cities ran firmware susceptible to CVE-2017-16740, a Modbus TCP buffer overflow affecting MicroLogix 1400 devices. Rockwell has released firmware revision 21.003 to address the flaw. The FBI also warned that attackers may have modified PLC project files, and similar third-party network setups could allow repeat compromises across customers.
Defenders are advised to take controllers off the public internet, use strong authentication, and isolate remote access through private APNs or VPNs. Rockwell’s advisory SD1790 provides recovery guidance for locked-out devices, emphasizing the need for offline backups of controller logic.
CVEs: CVE-2017-16740, CVE-2026-50522
Companies: Rockwell Automation, Forescout, Censys, Verizon Business, AT&T Mobility, T-Mobile USA
Products: MicroLogix 1400, MicroLogix 1100
Original source: thehackernews.com