CVE-2026-84235

8.7

Rockwell Automation · 1756-ENBT Module

A denial-of-service vulnerability in the Rockwell Automation 1756-ENBT module allows unauthenticated attackers to crash the device by sending a specially crafted CIP packet.

Executive summary

A high-severity denial-of-service vulnerability in the Rockwell Automation 1756-ENBT module allows remote attackers to force a system crash, necessitating a manual restart of the device.

Vulnerability

This vulnerability involves a denial-of-service condition triggered by a crafted Common Industrial Protocol (CIP) packet. The flaw is remotely exploitable by an unauthenticated attacker, requiring no user interaction to cause the module to cease operation.

Business impact

The exploitation of this vulnerability results in the immediate loss of availability for the affected industrial control module, which may lead to significant operational downtime. With a CVSS score of 8.7, this flaw poses a severe risk to production environments where continuous uptime is critical for safety and operational continuity.

Remediation

Immediate Action: Migrate to the recommended hardware replacements, specifically the 1756-EN2T or 1756-EN4TR modules, as the affected hardware is deprecated or inherently vulnerable.

Proactive Monitoring: Monitor industrial network traffic for malformed CIP packets or unexpected spikes in traffic directed toward the 1756-ENBT module that might indicate scanning or exploitation attempts.

Compensating Controls: Implement strict network segmentation and firewall rules to restrict access to the affected module, ensuring that only trusted engineering workstations can communicate with the device.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the critical nature of industrial control systems, the inability to patch the existing hardware necessitates an immediate review of the affected deployment. Organizations should prioritize replacing the vulnerable 1756-ENBT hardware with the recommended modern equivalents to eliminate this risk entirely.

More Rockwell Automation CVEs

Sources