Junglewise Threat Intelligence

CVE-2026-9140: Rockwell Automation 1718/1719-AENTR denial of service via UDP storm

CVE-2026-9140 · Severity: info · CVSS 8.7 · Published 2026-07-14

Vendors: Rockwell Automation.

Executive brief

Rockwell Automation EtherNet/IP adapters used in industrial environments are vulnerable to a denial-of-service attack. An attacker can send a flood of network traffic that causes the device to become unresponsive and lose communication with the control system. This disruption requires a physical power cycle to restore operations, potentially halting industrial processes.

Technical details

The vulnerability is classified as CWE-770 (Allocation of Resources Without Limits or Throttling) within the 1718-AENTR and 1719-AENTR firmware. The device fails to properly manage a UDP unicast network storm, leading to resource exhaustion and a complete loss of communication functionality. This is a network-based attack that requires no authentication or user interaction. The issue is resolved in firmware version 3.012.

Affected products

  • Rockwell Automation 1718-AENTR 3.011
  • Rockwell Automation 1719-AENTR 3.011

Timeline

  • 2026-07-14: advisory: Initial release of SD1778 by Rockwell Automation
  • 2026-07-14: patched: Firmware version 3.012 released to address the issue

References