Junglewise Threat Intelligence

CVE-2026-0646: Rockwell Automation 1794-AENTR denial of service via CIP requests

CVE-2026-0646 · Severity: info · CVSS 8.7 · Published 2026-06-16

Vendors: Rockwell Automation.

Executive brief

The Rockwell Automation 1794-AENTR is a communication adapter used in industrial settings to connect input/output modules to a control network. A security flaw in how this device handles network traffic can cause it to crash and lose connection to its connected hardware. If exploited, this would disrupt industrial processes and require a manual physical reset of the device to restore operations.

Technical details

A denial-of-service vulnerability exists in the Rockwell Automation 1794-AENTR and 1794-AENTRXT FLEX I/O EtherNet/IP adapters due to improper memory handling (CWE-401: Missing Release of Memory after Effective Lifetime). An unauthenticated attacker can exploit this by sending crafted Common Industrial Protocol (CIP) requests over the network. Successful exploitation causes the adapter to enter a fault state and lose communication with its associated I/O modules. Recovery from this state requires a manual reset of the hardware. The vulnerability is addressed in firmware version 2.013.

Affected products

  • Rockwell Automation 1794-AENTR / 1794-AENTRXT FLEX I/O EtherNet/IP Adapters 2.012

Timeline

  • 2026-05-20: disclosed: Initial internal release date noted in revision history
  • 2026-06-16: advisory: Public advisory published by Rockwell Automation and NVD
  • 2026-06-16: patched: Firmware version 2.013 released to address the issue

References

Related threats