Description
A denial-of-service security issue exists in the 1719-AENTR. The security issue stems from improper handling of a UDP unicast network storm, which causes the device to become overloaded and lose communication. A power cycle is required to recover.
Published: 2026-07-14
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability identified as a Resource Exhaustion weakness (CWE‑770) in the 1719‑AENTR device, and likely affecting 1718‑AENTR, causes the device to become overloaded when it receives a controlled UDP unicast network storm. The improper handling of the traffic leads to a loss of communication that can only be restored by physically cycling the power. The resulting impact is a denial of operations dependent on the device.

Affected Systems

Rockwell Automation 1718-AENTR and 1719-AENTR devices are affected.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity. The EPSS score of less than 1% shows that real‑world exploitation is currently very unlikely, and the vulnerability is not listed in CISA. Based on the description, it is inferred that an attacker would need network access to the device, which could be achieved from an internal network or from a compromised external point.

Generated by OpenCVE AI on July 31, 2026 at 10:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update or patch from Rockwell Automation for the 1718-AENTR/1719-AENTR devices.
  • If a patch is not available or pending, configure network segmentation or firewall rules to block or heavily throttle high‑volume UDP traffic directed at the device.
  • Implement network‑level measures to mitigate UDP storms before they reach the device.
  • If the device becomes unresponsive, perform a controlled power cycle and monitor for subsequent outages.

Generated by OpenCVE AI on July 31, 2026 at 10:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Description A denial-of-service security issue exists in the 1719-AENTR. The security issue stems from improper handling of a UDP unicast network storm, which causes the device to become overloaded and lose communication. A power cycle is required to recover.
Title 1718-AENTR/1719-AENTR - Denial of Service
Weaknesses CWE-770
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Rockwell

Published:

Updated: 2026-07-14T15:24:32.109Z

Reserved: 2026-05-20T19:35:43.256Z

Link: CVE-2026-9140

cve-icon Vulnrichment

Updated: 2026-07-14T15:24:28.068Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T10:30:17Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling