S4E just found a high top 10 tcp port service scan
critical·Product Based Network Vulnerabilities·Updated Dec 17, 2024

EtherNet/IP Devices Detection Scanner

This scanner detects the use of EtherNet/IP Devices on digital assets. It identifies device details such as vendor, product name, serial number, and IP address to facilitate asset discovery and inventory.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
Detail

EtherNet/IP is a widely used industrial automation protocol developed for communication in automation systems, including PLCs, sensors, and other devices. It is primarily used in manufacturing, process industries, and factory floor environments where real-time control is crucial. This scanner checks for devices running EtherNet/IP to ensure proper visibility and management of network-connected industrial devices.

This scanner focuses on detecting EtherNet/IP devices by sending specific identity requests to devices on TCP port 44818. It validates responses and extracts detailed information about the devices, such as vendor name, product name, serial number, and IP address. This allows administrators to identify the presence of devices and their details efficiently.

Technically, the scanner sends a crafted EtherNet/IP identity request packet to the target and parses the response for details. The endpoint being targeted is TCP port 44818, commonly associated with EtherNet/IP. The script checks for proper responses and decodes key information like device type, vendor ID, and revision number to assist in network management.

If exploited or improperly configured, EtherNet/IP devices may expose critical industrial control system details. Such information could be leveraged by attackers to disrupt processes or craft targeted attacks on industrial networks. Proper detection aids in risk assessment and mitigates potential threats to operational technology environments.

REFERENCES

Solution Advice

To mitigate issues related to the exposure of EtherNet/IP devices:

  • Ensure devices are behind a secure firewall and inaccessible directly from the public internet.
  • Implement strong access control policies for network devices.
  • Regularly update firmware and software to patch known vulnerabilities.
  • Conduct periodic security assessments and device audits.
  • Isolate industrial control systems from regular IT networks to limit potential attack vectors.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.