How to connect with an Ethernet/IP and CIP
Ethernet/IP stands for Ethernet Industrial Protocol. Despite the name, the “IP” does not just mean Internet Protocol. Instead, it means that this protocol uses standard Ethernet hardware and TCP/IP routing. This protocol uses the standard Ethernet but communicate using the object oriented language called the Common Industrial Protocol (CIP).
This CIP protocol responsible for controlling physical processes like read variables (tags), write values, start and stop machines and monitor sensors.
To do the communication EtherNet/IP typically uses 44818 TCP or 2222 UDP as the standard ports but can be customized.
- TCP 44818: Explicit messaging. This is a client/server request-response model used for non-time-critical operations like tag reads/writes and configuration.
- UDP 2222: Implicit messaging. This is used for real-time I/O control where devices continuously blast data back and forth.
PLCs stores variables as “tags”. In real factories tags have names like MotorSpeed, TankLevel or SafetyValveStatus. Because CIP is object-oriented, it maps these tags to specific Classes, Instances, and Attributes under the hood. When we query a PLC to read these tags, we execute a handshake.
Step 1: Register Session
Before sending any CIP commands, client must register an Ethernet/IP session.
Step 2: Send Unit Data
Client then wraps the CIP request inside an EhterNet/IP frame. In packet captures you can see this logged as an unconnected_send.service. This is standard CIP explicit Messaging.
Step 3: CIP Read Tag
The most critical part of the request is the service code. To read a tag, the client sends service: 76 (which is 0x4C in hex). This is the CIP service for Read Tag. You are explicitly asking the PLC: "Give me the value stored in this specific memory location."
service: 76
0x4C
To automate this entire handshake and extract tags programmatically, security researchers and engineers often use specialized Python modules like cpppo or pycomm3 to handle the complex CIP routing and encapsulation.
cpppo
pycomm3