Impact
A debug port on the 1715-AENTR EtherNet/IP Adapter is exposed without privilege controls, allowing any network user to connect and execute a command-line interface. The interface permits reading or deleting files, stopping tasks, modifying memory, and changing the I/O state of the device. Such capabilities could compromise the confidentiality, integrity, and availability of the instrument by enabling an attacker to alter operational parameters or remove critical data.
Affected Systems
Rockwell Automation’s 1715 EtherNet/IP Communications Module (1715-AENTR EtherNet/IP Adapter) is impacted. Firmware versions prior to 3.011 retain the unprotected debug port and are therefore vulnerable. The recommended remediation is to upgrade to version 3.011 or later.
Risk and Exploitability
The vulnerability carries a CVSS score of 10, marking it as critical, while the EPSS score of less than 1% indicates a presently low probability of exploitation. It is not listed in the CISA KEV catalog. However, because the exploit requires only remote network traffic to an exposed port and no authentication, the attack surface is simple and an attacker with network access to the device can obtain full command execution.
OpenCVE Enrichment