Sizing the S7comm Surface: What 262 Reachable Port 102 Services Actually Tell You
When joint advisory AA26-231A was published on 19 August 2026, one of its central claims was that attackers locate Siemens S7 controllers by scanning the internet for devices with port 102 exposed. A natural follow-up question is how large that population is. A ZoomEye host search for port:102 returned 262 observable services at the time of collection.
That number is smaller than many readers expect, and the gap between expectation and measurement is where the useful analysis lives.
What the query measures
port:102 asks ZoomEye for hosts where TCP port 102 responded to a connection attempt. Port 102 carries ISO-TSAP, the transport layer that Siemens S7comm runs over. The query does not require the responding service to be a Siemens PLC. It does not require the device to be a controller at all. It returns anything listening on that port that the scanner could reach.
The count is therefore an upper bound on reachable S7comm-speaking devices, not a lower bound. Some fraction of those 262 services will be S7 controllers. Some will be other industrial equipment that happens to use ISO-TSAP. Some will be honeypots, research systems or misconfigured development environments.
Why the number is lower than the advisory implies
The advisory describes an active threat, and readers often translate that into an assumption that exposed S7 controllers are numerous. The measurement suggests the reachable population on the open internet is modest, at least for the query as defined.
Three factors explain the gap. First, most S7 deployments are correctly placed behind network segmentation, which is exactly the control the advisory recommends. Second, internet-wide scans of industrial ports are noisier and slower than scans of web ports, so some reachable devices may not appear in a given index at a given time. Third, the population that matters to an attacker is not the global one but the one reachable from a specific vantage point, and a device behind a carrier NAT or a stateful firewall may not answer a scan from outside even though it is reachable from a specific network.
The comparison that matters more than the total
A single total is a weak signal. The more useful comparison is between port 102 and the other industrial protocol ports that carry similar risk. A ZoomEye query for port:502 returned 834 observable services, and port:20000 returned 2,412. Both Modbus on 502 and DNP3 on 20000 are protocols with weak or absent authentication in common deployments, and both are more numerous in this measurement than S7comm.
That ordering is worth noting, because the advisory that prompted this analysis named Siemens specifically. The exposure pattern is not brand-specific. An organisation that runs Modbus or DNP3 devices on reachable networks has a structurally similar problem, even though no advisory has named it.
How to use this in an assessment
The practical use of a count like 262 is as a baseline for your own environment, not as a global risk statement. Run the equivalent query against your own address space, or ask your asset inventory team to enumerate everything listening on 102, 502, 44818 and 20000. The number you get is the one that matters.
If that number is zero, the advisory's reachability recommendation is already satisfied and the remaining work is detection and access protection. If it is not zero, the priority order from the advisory applies directly: confirm the device is not reachable from an untrusted network, block the port at the perimeter, enable the controller's own access protection, and instrument for anomalous protocol traffic.
Limits of this analysis
The count reflects one query, one index and one moment. It is not a census of global S7 deployment, and it should not be cited as one. It also cannot distinguish a protected controller from an unprotected one, because that distinction requires an authenticated interaction that a responsible measurement does not perform.
What it can do is replace an assumption with a measurement. The assumption was that internet-exposed S7 controllers are everywhere. The measurement says the reachable population on this port is in the low hundreds, and that adjacent industrial protocols are more exposed. Both facts are useful, and neither is a reason to relax.
References
- CISA, NSA, FBI, DOE and EPA, joint cybersecurity advisory AA26-231A, 19 August 2026: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a
- ZoomEye host search, dorks
port:102,port:502,port:20000, collected 18 September 2026
Top comments (0)