Description
A denial-of-service security issue exists in the affected product. The security issue stems from a crafted CIP packet being sent crashing the module. The device requires a restart to recover.
Published: 2026-09-01
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Module
AI Analysis

Impact

Denial‑of‑service vulnerability in the Rockwell Automation 1756‑ENBT Module causes the device to crash when it receives a specially crafted CIP packet. The module must be restarted to resume operation; no additional insight into the internal fault mechanism is provided by the advisory.

Affected Systems

All versions of the Rockwell Automation 1756‑ENBT Module, as identified by the vendor entry and the associated product listing, are affected. The module is a physical controller component distributed by Rockwell Automation.

Risk and Exploitability

The flaw carries a CVSS score of 8.7, indicating high severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the CIP network: an adversary with network access to the module can send a tailored packet to trigger the crash, resulting in downtime that requires a manual restart. The risk is elevated in environments lacking network segmentation or proper firewall controls around the device.

Generated by OpenCVE AI on September 2, 2026 at 05:25 UTC.

Remediation

Vendor Solution

Upgrade to 1756-EN2T or 1756-EN4TR


OpenCVE Recommended Actions

  • Upgrade the Rockwell Automation 1756‑ENBT Module to firmware 1756‑EN2T or 1756‑EN4TR to eliminate the denial‑of‑service vulnerability.
  • Apply network segmentation or firewall rules to restrict CIP traffic to trusted sources, reducing the chance that a malicious packet reaches the module.
  • Monitor module logs for unexpected crashes; if an unpatched unit must remain online, schedule automated restarts during low‑traffic periods.

Generated by OpenCVE AI on September 2, 2026 at 05:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Rockwellautomation
Rockwellautomation 1756-enbt/a
Vendors & Products Rockwellautomation
Rockwellautomation 1756-enbt/a

Wed, 02 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-400
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description A denial-of-service security issue exists in the affected product. The security issue stems from a crafted CIP packet being sent crashing the module. The device requires a restart to recover.
Title Rockwell Automation 1756-ENBT Denial of Service Vulnerability
First Time appeared Rockwell Automation
Rockwell Automation 1756-enbt Module
CPEs cpe:2.3:a:rockwell_automation:1756-enbt_module:all_versions:*:*:*:*:*:*:*
Vendors & Products Rockwell Automation
Rockwell Automation 1756-enbt Module
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Rockwell Automation 1756-enbt Module
Rockwellautomation 1756-enbt/a
cve-icon MITRE

Status: PUBLISHED

Assigner: Rockwell

Published:

Updated: 2026-09-01T15:41:57.774Z

Reserved: 2026-09-01T12:56:28.970Z

Link: CVE-2026-84235

cve-icon Vulnrichment

Updated: 2026-09-01T15:41:54.631Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-01T13:20:09.563

Modified: 2026-09-01T20:50:01.960

Link: CVE-2026-84235

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T16:28:14Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption