VYPR
advisoryPublished Jul 21, 2026· 2 sources

CISA Warns of Denial-of-Service Vulnerability in Rockwell Automation Communication Modules

CISA has issued a critical advisory for Rockwell Automation's 1718-AENTR/1719-AENTR devices, detailing a denial-of-service vulnerability that could disrupt industrial control systems.

CISA has issued a critical advisory for Rockwell Automation's 1718-AENTR and 1719-AENTR communication modules, detailing a vulnerability that could lead to a denial-of-service (DoS) condition. The vulnerability, identified as CVE-2026-9140, stems from the devices' improper handling of UDP unicast network storms. This flaw can cause the affected devices to become overloaded, resulting in a loss of communication that necessitates a full power cycle to resolve.

The affected products include Rockwell Automation's 1718/1719 Ex I/O versions prior to 3.012. The vulnerability has been assigned a CVSS v3.1 base score of 7.5, classifying it as HIGH severity. The attack vector is network-based, requiring no authentication or privileges, and can lead to a complete loss of availability for the affected device. This type of vulnerability is particularly concerning in industrial control systems (ICS) environments where continuous operation is critical.

Successful exploitation of CVE-2026-9140 could allow an unauthenticated attacker to flood the device with UDP unicast traffic, overwhelming its resources. This overload would disrupt normal operations and cause the device to cease functioning, effectively creating a denial-of-service. The only means of recovery, according to the advisory, is to power cycle the affected module, which can cause significant downtime in a production environment.

Rockwell Automation has released a fix for this vulnerability, recommending that users upgrade to version 3.012 or later of the 1718/1719 Ex I/O firmware. For organizations unable to immediately upgrade, Rockwell Automation suggests implementing their security best practices to mitigate the risk. These practices often include network segmentation, access control, and regular security monitoring.

CISA strongly recommends that organizations take defensive measures to minimize the risk of exploitation. These measures include minimizing network exposure for all control system devices, ensuring they are not accessible from the internet, and locating control system networks behind firewalls and isolating them from business networks. Secure remote access methods, such as VPNs, should be used when necessary, with the understanding that VPNs themselves require regular updates and secure configurations.

While no known public exploitation of this specific vulnerability has been reported to CISA at this time, the nature of ICS vulnerabilities means that successful attacks could have severe consequences for critical infrastructure sectors, including critical manufacturing. The worldwide deployment of these Rockwell Automation devices underscores the broad potential impact.

CISA also reminds organizations to perform thorough impact analyses and risk assessments before deploying any defensive measures. Implementing recommended cybersecurity strategies for proactive defense of ICS assets, such as those detailed in CISA's ICS-TIP-12-146-01B, is crucial for maintaining the security and operational integrity of industrial environments. Organizations observing suspicious activity should follow internal procedures and report findings to CISA.

This advisory highlights the ongoing challenges in securing industrial control systems against denial-of-service attacks. The reliance on UDP unicast traffic, a common protocol in industrial networking, makes such vulnerabilities a persistent threat. Prompt patching and adherence to security best practices remain the most effective defenses against these types of threats.

This advisory updates previous reports on Rockwell Automation communication modules by detailing a specific denial-of-service vulnerability, CVE-2026-10573, affecting the 1734 POINT I/O module version 3.023. The vulnerability arises from improper handling of crafted CIP messages, leading to a module fault that requires a restart for recovery. While Rockwell Automation suggests migrating to the 5034-OB8 or implementing security best practices, no known public exploitation has been reported to CISA at this time.

Synthesized by Vypr AI