Impact
Denial‑of‑service vulnerability in the Rockwell Automation 1756‑ENBT Module causes the device to crash when it receives a specially crafted CIP packet. The module must be restarted to resume operation; no additional insight into the internal fault mechanism is provided by the advisory.
Affected Systems
All versions of the Rockwell Automation 1756‑ENBT Module, as identified by the vendor entry and the associated product listing, are affected. The module is a physical controller component distributed by Rockwell Automation.
Risk and Exploitability
The flaw carries a CVSS score of 8.7, indicating high severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the CIP network: an adversary with network access to the module can send a tailored packet to trigger the crash, resulting in downtime that requires a manual restart. The risk is elevated in environments lacking network segmentation or proper firewall controls around the device.
OpenCVE Enrichment