Executive brief
Rockwell Automation EtherNet/IP adapters used in industrial environments are vulnerable to a denial-of-service attack. An attacker can send a flood of network traffic that causes the device to become unresponsive and lose communication with the control system. This disruption requires a physical power cycle to restore operations, potentially halting industrial processes.
Technical details
The vulnerability is classified as CWE-770 (Allocation of Resources Without Limits or Throttling) within the 1718-AENTR and 1719-AENTR firmware. The device fails to properly manage a UDP unicast network storm, leading to resource exhaustion and a complete loss of communication functionality. This is a network-based attack that requires no authentication or user interaction. The issue is resolved in firmware version 3.012.
Affected products
- Rockwell Automation 1718-AENTR 3.011
- Rockwell Automation 1719-AENTR 3.011
Timeline
- 2026-07-14: advisory: Initial release of SD1778 by Rockwell Automation
- 2026-07-14: patched: Firmware version 3.012 released to address the issue