Executive brief
The Rockwell Automation 1794-AENTR is a communication adapter used in industrial settings to connect input/output modules to a control network. A security flaw in how this device handles network traffic can cause it to crash and lose connection to its connected hardware. If exploited, this would disrupt industrial processes and require a manual physical reset of the device to restore operations.
Technical details
A denial-of-service vulnerability exists in the Rockwell Automation 1794-AENTR and 1794-AENTRXT FLEX I/O EtherNet/IP adapters due to improper memory handling (CWE-401: Missing Release of Memory after Effective Lifetime). An unauthenticated attacker can exploit this by sending crafted Common Industrial Protocol (CIP) requests over the network. Successful exploitation causes the adapter to enter a fault state and lose communication with its associated I/O modules. Recovery from this state requires a manual reset of the hardware. The vulnerability is addressed in firmware version 2.013.
Affected products
- Rockwell Automation 1794-AENTR / 1794-AENTRXT FLEX I/O EtherNet/IP Adapters 2.012
Timeline
- 2026-05-20: disclosed: Initial internal release date noted in revision history
- 2026-06-16: advisory: Public advisory published by Rockwell Automation and NVD
- 2026-06-16: patched: Firmware version 2.013 released to address the issue