Thousands of Rockwell PLCs Exposed Online Amid Water-Utility Attacks

1 min read
Source: The Hacker News
Thousands of Rockwell PLCs Exposed Online Amid Water-Utility Attacks
Photo: The Hacker News
TL;DR Summary

Forescout counted 4,407 exposed Rockwell/Allen‑Bradley PLCs worldwide (2,844 in the U.S.) as of Aug. 3, with 22 internet-facing in cities affected by recent water-utility cyberattacks. Attackers could disrupt operations by changing IPs or passwords on already-accessible controllers, even without exploiting a vulnerability; 19 of the 22 exposed units ran firmware susceptible to CVE-2017-16740. Many exposed devices are on large mobile carrier networks (about 70% of U.S. exposed controllers). Authorities advise removing public Internet exposure, enforcing strong authentication, and using VPNs/private networks. A separate recovery advisory exists for resetting affected MicroLogix 1400/1100 PLCs to default and restoring known-good projects, but it requires offline backups. No agency has publicly attributed the campaign yet, and researchers caution that similar configurations could enable broader compromises.

Share this article

Reading Insights

Total Reads

0

Unique Readers

6

Time Saved

2 min

vs 3 min read

Condensed

78%

544121 words

Want the full story? Read the original article

Read on The Hacker News