Description
A denial-of-service security issue exists across all the 1756-EN2, EN3, and ENBT communication module due to improper validation of CIP Implicit Connection packets. An attacker on the network can exploit this by sending crafted packets to continuously disrupt device connections, though device connections will recover immediately after.
Published: 2026-07-14
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability stems from inadequate validation of CIP Implicit Connection packets in Rockwell Automation 1756-EN2, EN3, and ENBT communication modules. By sending crafted packets over the network, an attacker can repeatedly interrupt device connections, causing temporary service disruption; connections recover immediately but overall availability is impaired. This flaw permits remote denial of service and is classified as CWE-354.

Affected Systems

Rockwell Automation’s 1756-EN2, 1756-EN3, and 1756-ENBT communication modules are all affected; no specific firmware version ranges are cited, indicating that all current releases of these models are vulnerable.

Risk and Exploitability

The CVSS score of 8.7 signifies high severity, yet the EPSS score is below 1%, implying low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an attacker with network access capable of transmitting crafted CIP packets, and the likely attack vector is local or remote on the same network segment. Given the severity and the vulnerability’s remote nature, the risk remains significant even with a low likelihood.

Generated by OpenCVE AI on July 31, 2026 at 10:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official firmware update released by Rockwell Automation that adds proper validation for CIP Implicit Connection packets (see the advisory at www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1780.html).
  • If a firmware update cannot be applied immediately, limit CIP traffic by configuring firewalls or ACLs to reject packets from untrusted sources or to a strict port range used by CIP.
  • Disable CIP Implicit Connections on the not required, reducing the attack surface.

Generated by OpenCVE AI on July 31, 2026 at 10:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Description A denial-of-service security issue exists across all the 1756-EN2, EN3, and ENBT communication module due to improper validation of CIP Implicit Connection packets. An attacker on the network can exploit this by sending crafted packets to continuously disrupt device connections, though device connections will recover immediately after.
Title 1756-EN2, 1756-EN3, and 1756-ENBT - Denial of Service via CIP Connection ID
Weaknesses CWE-354
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Rockwell

Published:

Updated: 2026-07-14T15:25:27.797Z

Reserved: 2026-05-26T20:07:05.996Z

Link: CVE-2026-9653

cve-icon Vulnrichment

Updated: 2026-07-14T15:25:24.088Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T10:30:17Z

Weaknesses
  • CWE-354

    Improper Validation of Integrity Check Value