Critical Rockwell Automation Flaw Exposes Water Systems to Cyberattacks
Key Takeaways Thousands of Rockwell Automation/Allen-Bradley Programmable Logic Controllers (PLCs) remain directly exposed to the internet, particularly in critical water and wastewater...
Key Takeaways
- Thousands of Rockwell Automation/Allen-Bradley Programmable Logic Controllers (PLCs) remain directly exposed to the internet, particularly in critical water and wastewater infrastructure.
- A recent wave of cyberattacks has targeted U.S. water systems, exploiting these internet-facing PLCs and causing operational disruptions.
- The attacks have leveraged vulnerabilities in specific MicroLogix models, with threat actors modifying PLC logic or locking out operators.
- Immediate action is required for critical infrastructure operators to secure PLCs, implement robust remote access controls, and upgrade or replace vulnerable equipment.
Critical Rockwell Automation Flaw Exposes Water Systems to Cyberattacks
Recent cyberattacks against U.S. water and wastewater utilities have reignited concerns regarding the widespread exposure of industrial control systems to the public internet. New analysis reveals thousands of critical devices are readily accessible, creating a significant attack surface for malicious actors.
Table Of Content
Widespread Exposure of Rockwell PLCs
Research conducted by Forescout has identified 4,407 Rockwell Automation/Allen-Bradley Programmable Logic Controllers (PLCs) that are directly reachable from the internet, exposing port 44818, which is used by the EtherNet/IP engineering protocol. A staggering 65% of these exposed devices are located in the United States, with Canada accounting for 12% and Spain for 3%.
While this figure represents a 47% reduction from a peak of 7,814 exposed devices in March 2020, and a low of 4,169 in June 2026, the sheer volume of accessible systems continues to leave vital infrastructure vulnerable to compromise.
Coordinated Attacks Target Water Utilities
On July 28, Minnesota IT Services (MNIT) reported a coordinated cyberattack impacting over 30 water systems across the state. While no instances of degraded water quality were confirmed, operational disruptions were reported in cities including Plymouth, South St. Paul, Maple Plain, and Braham.
Braham authorities indicated that attackers utilized malware delivered via a wireless connection to disable water plant controls. Plymouth reported that the affected equipment, which included two water towers and 14 sewer lift stations, was connected through cellular routers.
Just two days later, the FBI and EPA issued a joint advisory, confirming similar incidents in at least 12 states since July 27, with Michigan, South Dakota, and Georgia later identified as affected regions.
Vulnerable Devices and Attack Vectors
The advisory disclosed that threat actors specifically targeted Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 PLCs. In some cases, attackers modified PLC logic or remotely altered IP addresses and passwords, effectively locking out legitimate operators. Reported consequences included pressure loss and flooding, raising serious concerns about the potential for untreated groundwater to contaminate drinking water supplies.
Analysis shows that MicroLogix 1400 devices constitute approximately 50% of the exposed controllers, followed by CompactLogix 1769 at 22%. MicroLogix 1100 and ControlLogix 5590 each account for 8%. Notably, over 70% of U.S.-based controllers are situated within major mobile carrier networks, connected via cellular routers, a configuration that aligns with the access method described in the FBI/EPA advisory.
Among 22 exposed hosts identified in cities targeted during the recent campaign, 86% shared the same mobile carrier network. Although no specific CVE has been definitively linked as the exploitation vector in these attacks, firmware analysis revealed that 19 of these 22 hosts were susceptible to CVE-2017-16740, a Modbus TCP denial-of-service vulnerability.
Forescout researchers also uncovered additional vulnerabilities such as expired certificates, abandoned remote-access hostnames, and forgotten servers associated with municipal utilities. This evidence points to incomplete asset visibility, exacerbating the overall risk beyond just the PLCs themselves.
What You Should Do
- Disconnect PLCs from the Public Internet: Ensure that all Programmable Logic Controllers are not directly accessible from the internet.
- Disable Unused Services: Deactivate unnecessary services, such as SNMP, on all industrial control devices.
- Restrict Port Access: Implement strict allowlists to control access to Modbus TCP and port 44818.
- Secure Cellular Gateways: Move cellular gateways to private carrier APNs or protect them with VPNs. Disable public administration interfaces.
- Enforce Multi-Factor Authentication: Mandate individual accounts with multi-factor authentication for all remote access.
- Plan Firmware Upgrades: Schedule and perform firmware upgrades for MicroLogix 1400 devices.
- Prioritize Replacement of End-of-Life Equipment: Replace MicroLogix 1100 devices, which Rockwell discontinued in April 2022.
- Implement Secure Remote Access (SRA) Gateways: Utilize SRA gateways to isolate user sessions from direct protocol access, providing a crucial layer of protection for remote operations.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.