Executive brief
The Rockwell Automation 1756-ENBT module is an EtherNet/IP bridge used in industrial automation systems to connect ControlLogix controllers to Ethernet devices. A vulnerability allows an attacker to send a specially crafted CIP (Common Industrial Protocol) packet that crashes the module, forcing a manual restart and disrupting production operations. No patch is currently available.
Technical details
This is a denial-of-service vulnerability in the CIP packet parsing logic of the 1756-ENBT module. A remote attacker can send a malformed CIP packet over the network to trigger a crash in the affected device, which requires manual intervention to restart. The vulnerability affects all firmware versions of the 1756-ENBT, 1756-EWEB, and L3xX catalog numbers. No permanent fix has been released; Rockwell Automation recommends upgrading to the 1756-EN2T or 1756-EN4TR modules as a replacement, or implementing network-based security controls as a workaround.
Affected products
- Rockwell Automation 1756-ENBT all versions
- Rockwell Automation 1756-EWEB all versions
- Rockwell Automation L3xX all versions
Timeline
- 2026-09-01: disclosed
- 2026-09-01: advisory: Rockwell Automation SD1798