Impact
The vulnerability stems from inadequate validation of CIP Implicit Connection packets in Rockwell Automation 1756-EN2, EN3, and ENBT communication modules. By sending crafted packets over the network, an attacker can repeatedly interrupt device connections, causing temporary service disruption; connections recover immediately but overall availability is impaired. This flaw permits remote denial of service and is classified as CWE-354.
Affected Systems
Rockwell Automation’s 1756-EN2, 1756-EN3, and 1756-ENBT communication modules are all affected; no specific firmware version ranges are cited, indicating that all current releases of these models are vulnerable.
Risk and Exploitability
The CVSS score of 8.7 signifies high severity, yet the EPSS score is below 1%, implying low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an attacker with network access capable of transmitting crafted CIP packets, and the likely attack vector is local or remote on the same network segment. Given the severity and the vulnerability’s remote nature, the risk remains significant even with a low likelihood.
OpenCVE Enrichment