Despite federal warnings, thousands of U.S. industrial controllers used in water systems remain exposed online
A new scan of internet-connected industrial equipment found over 4,000 Rockwell Automation and Allen-Bradley controllers exposed online, including 22 in cities impacted by cyberattacks on U.S. water systems.
The findings, published Wednesday by Forescout’s Vedere Labs, show that direct internet access to equipment used in water and wastewater operations remains common despite years of warnings from manufacturers and federal agencies.
The exposed devices use EtherNet/IP, an industrial protocol that allows for communication between control equipment, engineering workstations and other systems. When the port is open to the public internet, outside users may be able to identify devices and, depending on their setup, change settings or write new configurations.
The scan, run through the Shodan search engine Monday, found that 2,844 of the exposed controllers (65%) were in the United States.
The FBI and Environmental Protection Agency issued a joint advisory last week confirming attacks at water and wastewater utilities in at least 12 states since July 27. Officials have since named Michigan, South Dakota and Georgia among the affected states. Nine systems were hit in Michigan, and one wastewater lift station was hit in South Dakota.
Several reports have linked the attacks to Iranian actors, but Sai Molige, senior manager of threat hunting at Forescout, says the company has not attributed this activity to any actor or group.
“The evidence supports opportunistic, at-scale exploitation of a known class of vulnerabilities affecting internet-exposed devices,” Molige told CyberScoop. “The scale and speed of the activity are more consistent with mass scanning and enumeration than with zero-day exploitation, a months-long intrusion campaign, or custom malware.”
The advisory said attackers targeted programmable logic controllers (PLCs) made by Rockwell Automation under its Allen-Bradley brand, specifically the MicroLogix 1100 and 1400 models. In at least one case, attackers reached controllers remotely and changed their IP addresses and passwords, cutting off the utility’s own view and control of the equipment. The advisory said the attacks caused pressure loss and flooding.
Forescout’s research states that the most common exposed device family was the MicroLogix 1400, which made up half of the devices found. Other versions, such as AllenBradley’s CompactLogix 1769 controllers, made up 22%. MicroLogix 1100 and ControlLogix 5590 devices each accounted for about 8%.
Forescout cross-referenced those machines against the recently targeted cities and municipalities and found 22 devices still exposed to the internet. However, the company did not say those systems had been attacked or that they belonged to the affected utilities.
The research also found that 19 of the 22 hosts in affected cities appeared, based on firmware versions, to be open to CVE-2017-16740, a remote code execution flaw disclosed in 2017 that impacts MicroLogix 1400 devices. An attacker would need Modbus TCP enabled to use that flaw, and the researchers could not confirm whether the affected systems had it enabled.
Rockwell Automation and other industrial equipment makers have warned customers not to place controllers directly on the public internet as far back as 2018.
Beyond the controllers, the researchers also looked at the digital records tied to these utilities. They found expired certificates, remote-access web addresses left unrenewed for months or years, and servers that appear abandoned — in one case, a server that has shown nothing but a default Microsoft webpage since April 2019.
“These stale services can increase the attack surface; however, we have not yet confirmed how the observed attacks occurred,” Molige told CyberScoop.