VYPR
advisoryPublished Sep 3, 2026· 1 source

CISA Warns of Denial-of-Service Vulnerability in Rockwell Automation 1756-ENBT Module

A critical vulnerability in Rockwell Automation's 1756-ENBT module could allow attackers to crash the device, requiring a manual restart.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an advisory detailing a critical denial-of-service (DoS) vulnerability affecting Rockwell Automation's 1756-ENBT module. This industrial control system component serves as an EtherNet/IP bridge, facilitating communication between Logix 5000 controllers and various Ethernet-enabled devices.

The vulnerability, identified as CVE-2025-10478, stems from an "Improper Check for Unusual or Exceptional Conditions." Exploitation involves an attacker sending a specifically crafted CIP (Common Industrial Protocol) packet to the affected module. Successful delivery of this malicious packet can trigger a crash, rendering the module inoperable and disrupting critical industrial processes.

According to CISA, the impact of this vulnerability is a denial-of-service condition. Once the 1756-ENBT module crashes, it requires a manual restart to restore functionality. This downtime can have significant consequences in operational technology (OT) environments, potentially leading to production stoppages and financial losses.

The advisory states that all versions of the Rockwell Automation 1756-ENBT module are affected by this vulnerability. The affected product is crucial in sectors such as Critical Manufacturing, Food and Agriculture, Transportation Systems, and Water and Wastewater, with deployments reported worldwide.

Rockwell Automation has provided remediation guidance, recommending that users upgrade to newer, more secure modules such as the 1756-EN2T or 1756-EN4TR. For organizations unable to perform an immediate upgrade, Rockwell suggests adhering to their established security best practices.

The Common Vulnerabilities and Exposures (CVE) scoring for this vulnerability indicates a high severity. The CVSS v3.1 base score is 7.5 (HIGH), with a vector string of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, highlighting the network accessibility and lack of privileges or user interaction required for exploitation, with a complete impact on availability.

CISA strongly advises organizations to implement defensive measures to minimize the risk of exploitation. These recommendations include minimizing network exposure for all control system devices, ensuring they are not accessible from the internet, and locating control system networks behind firewalls, isolating them from business networks. Secure remote access methods like VPNs should be employed when necessary, with an emphasis on keeping VPNs updated.

While no public exploitation targeting this specific vulnerability has been reported to CISA at this time, the advisory serves as a proactive warning. Organizations are encouraged to conduct thorough impact analyses and risk assessments before deploying any defensive measures and to report any suspected malicious activity to CISA.

Synthesized by Vypr AI