Port 44818: EtherNet/IP (Common Industrial Protocol) explicit messaging
IANA registers 44818 over TCP and UDP as EtherNet/IP-2 (EtherNet/IP messaging) and 2222 as EtherNet/IP-1 (EtherNet/IP I/O). EtherNet/IP carries the Common Industrial Protocol (CIP) used by industrial controllers covered in CISA ICS advisories.
Port Details
Security Exposure
CISA ICS advisories describe valid CIP messages from unauthorized sources on 44818 and 2222 causing IP changes, resets and denial of service on controllers. For CVE-2021-22681, an unauthenticated attacker could bypass the verification mechanism and authenticate with Logix controllers; CISA added the CVE to its KEV catalog in March 2026, and the advisory lists restricting TCP 44818 from outside the control system zone as a mitigation.
Hardening
- +Block EtherNet/IP traffic on 44818 and 2222 from outside the manufacturing zone using firewalls or UTM devices.
- +Deploy CIP Security where devices support it to add TLS and DTLS protection.
- +On ControlLogix 5580 v32 or later, put the controller mode switch in Run mode as Rockwell recommends for CVE-2021-22681.
- +Apply vendor firmware updates listed in CISA ICS advisories.
Monitoring
Use OT-aware network monitoring to baseline which engineering workstations send CIP commands, and alert on program downloads, mode changes, or 44818 sessions from unknown hosts.
EtherNet/IP Vulnerabilities
3 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2021-22681 | Rockwell Multiple Products Insufficient Protected Credentials Vulnerability | - | 9.8 | 63.6% | KEV | 2021-03-03 |
| CVE-2017-12234 | Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability | - | 7.5 | 7.1% | KEV | 2017-09-28 |
| CVE-2017-12233 | Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability | - | 7.5 | 7.1% | KEV | 2017-09-28 |
Tools for Auditing and Monitoring EtherNet/IP
Claroty
CommercialCPS protection platform spanning OT, IoT, and medical devices with monitoring, access, and exposure modules.
Nozomi Networks
CommercialOT and IoT visibility platform with AI-driven anomaly detection across industrial networks.
Dragos
CommercialOT cybersecurity platform for asset visibility, vulnerability prioritization, and ICS threat detection.
Related Tool Categories
Packet capture tools, protocol analyzers, and network security monitors for traffic visibility.
Zero trust access, secure web gateways, firewalls, and perimeter enforcement platforms.
Industrial network monitoring, ICS protocol analysis, and OT asset inventory platforms.
Frequently Asked Questions
What is port 44818 used for?→
IANA registers it for EtherNet/IP messaging with industrial controllers and devices.
Is port 44818 TCP or UDP?→
Both. IANA registers TCP and UDP 44818, and CISA advisories reference both transports.
Should port 44818 be reachable from the internet?→
No. CISA advisories recommend blocking EtherNet/IP traffic from outside the industrial control system zone.
Which vulnerabilities affect the service on port 44818?→
This database lists 3 CVEs related to EtherNet/IP, 3 of them confirmed as exploited by CISA. Examples: CVE-2021-22681, CVE-2017-12234, CVE-2017-12233.
Sources
- IANA Service Name and Port Number Registry (CSV)
- CISA ICS Advisory ICSA-21-056-03: Rockwell Automation Logix Controllers
- CISA ICS Advisory ICSA-13-011-03: Rockwell Automation ControlLogix PLC Vulnerabilities
- CISA ICS Advisory ICSA-18-310-02: Rockwell Automation MicroLogix 1400 and 1756 ControlLogix
- CISA Known Exploited Vulnerabilities Catalog
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 44818 is not guaranteed to be EtherNet/IP. Exploited-in-the-wild data from the CISA KEV catalog (CC0).