B
今週中
ForescoutのVedere Labsによる調査で、4,000台以上のRockwell AutomationおよびAllen-Bradley製産業用コントロ…
📌 一言でいうと
ForescoutのVedere Labsによる調査で、4,000台以上のRockwell AutomationおよびAllen-Bradley製産業用コントローラーがインターネットに直接公開されていることが判明しました。特に米国の水・廃水処理施設で多く見られ、攻撃者が設定変更や不正な構成の書き込みを行うリスクがあります。FBIとEPAは、すでに複数の州で水インフラへの攻撃を確認し、注意を呼びかけています。
🔍該当判定
- Rockwell Automation社またはAllen-Bradley社の産業用コントローラ(PLC)を利用している
- 上記機器を、VPNなどを介さず直接インターネットに接続して外部から操作できるようにしている
- 工場や水処理施設などの設備制御にEtherNet/IPプロトコルを使用している
上記いずれにも該当しない → 静観でOK
✅該当時の対応
産業用コントローラーをパブリックインターネットから隔離し、VPNやファイアウォールを用いてアクセス制限を徹底すること。また、EtherNet/IPなどの産業用プロトコルのポートが外部に公開されていないか、Shodan等のツールを用いて自社資産の露出状況を確認することを推奨します。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】Rockwell Automation/Allen-Bradley製コントローラーのインターネット露出について
お疲れさまです。産業用制御システムのセキュリティに関する情報共有です。
■ 概要
Rockwell AutomationおよびAllen-Bradley製のコントローラーが、インターネットに直接公開された状態で運用されている事例が多数報告されています。EtherNet/IPプロトコルのポートが公開されている場合、外部からデバイスの特定や設定変更が行われる危険性があります。
■ 影響範囲
- 対象製品: Rockwell Automation / Allen-Bradley 製産業用コントローラー
- 対象プロトコル: EtherNet/IP
■ 対応手順
1. 外部から産業用コントローラーへ直接アクセス可能な経路がないか、ネットワーク構成およびファイアウォール設定を確認してください。
2. 制御系ネットワークをインターネットから完全に隔離し、必要に応じてVPN等のセキュアなアクセス手段を導入してください。
3. Shodan等の外部スキャンツールを用いて、自社資産が意図せず公開されていないか確認してください。
■ 参考情報
- Forescout Vedere Labs 調査レポート
- FBI/EPA 合同アドバイザリ
対応優先度: 高
対応期限: 速やかに確認
お疲れさまです。産業用制御システムのセキュリティに関する情報共有です。
■ 概要
Rockwell AutomationおよびAllen-Bradley製のコントローラーが、インターネットに直接公開された状態で運用されている事例が多数報告されています。EtherNet/IPプロトコルのポートが公開されている場合、外部からデバイスの特定や設定変更が行われる危険性があります。
■ 影響範囲
- 対象製品: Rockwell Automation / Allen-Bradley 製産業用コントローラー
- 対象プロトコル: EtherNet/IP
■ 対応手順
1. 外部から産業用コントローラーへ直接アクセス可能な経路がないか、ネットワーク構成およびファイアウォール設定を確認してください。
2. 制御系ネットワークをインターネットから完全に隔離し、必要に応じてVPN等のセキュアなアクセス手段を導入してください。
3. Shodan等の外部スキャンツールを用いて、自社資産が意図せず公開されていないか確認してください。
■ 参考情報
- Forescout Vedere Labs 調査レポート
- FBI/EPA 合同アドバイザリ
対応優先度: 高
対応期限: 速やかに確認
Subject: [Security Alert] Exposure of Rockwell Automation/Allen-Bradley Controllers to Public Internet
Dear IT/Security Team,
We are sharing critical information regarding the exposure of industrial control systems.
■ Overview
Recent scans have identified over 4,000 Rockwell Automation and Allen-Bradley controllers exposed to the public internet. Devices using the EtherNet/IP protocol are particularly vulnerable, as attackers may be able to identify devices and modify configurations if the ports are open.
■ Scope
- Affected Products: Rockwell Automation / Allen-Bradley Industrial Controllers
- Affected Protocol: EtherNet/IP
■ Action Plan
1. Audit network configurations and firewall rules to ensure industrial controllers are not directly accessible from the public internet.
2. Isolate OT networks from the IT network and the internet, implementing secure access methods such as VPNs.
3. Use external scanning tools (e.g., Shodan) to verify that no corporate assets are unintentionally exposed.
■ Reference
- Forescout Vedere Labs Report
- FBI/EPA Joint Advisory
Priority: High
Deadline: Immediate review
Dear IT/Security Team,
We are sharing critical information regarding the exposure of industrial control systems.
■ Overview
Recent scans have identified over 4,000 Rockwell Automation and Allen-Bradley controllers exposed to the public internet. Devices using the EtherNet/IP protocol are particularly vulnerable, as attackers may be able to identify devices and modify configurations if the ports are open.
■ Scope
- Affected Products: Rockwell Automation / Allen-Bradley Industrial Controllers
- Affected Protocol: EtherNet/IP
■ Action Plan
1. Audit network configurations and firewall rules to ensure industrial controllers are not directly accessible from the public internet.
2. Isolate OT networks from the IT network and the internet, implementing secure access methods such as VPNs.
3. Use external scanning tools (e.g., Shodan) to verify that no corporate assets are unintentionally exposed.
■ Reference
- Forescout Vedere Labs Report
- FBI/EPA Joint Advisory
Priority: High
Deadline: Immediate review