Executive brief
Rockwell Automation 1715-AENTR EtherNet/IP Adapters, which are used to manage redundant industrial communications, contain a security flaw that exposes a debug port to the network without requiring a password. An attacker could use this access to take full control of the device, allowing them to stop industrial tasks, delete files, or manipulate physical I/O states. This could lead to significant operational downtime, equipment damage, or safety risks in industrial environments.
Technical details
A vulnerability classified as Missing Authentication for Critical Function (CWE-306) exists in the 1715-AENTR EtherNet/IP Adapter firmware. The device exposes a network-accessible debug port that fails to enforce privilege controls or authentication. A remote, unauthenticated attacker can connect to this port to access a command-line interface (CLI) with high-level permissions. Successful exploitation allows the attacker to read/delete files, terminate system tasks, modify memory, and change I/O states. The issue is resolved in firmware version 3.011.
Affected products
- Rockwell Automation 1715-AENTR EtherNet/IP Adapter 3.003 and prior
Timeline
- 2026-07-14: advisory: Initial release of SD1785 by Rockwell Automation
- 2026-07-14: patched: Firmware version 3.011 released to address the issue