Rockwell Automation 1756-EN2/EN3/ENBT CIP Implicit Connection Denial-of-Service Vulnerability
First seen Jul 18, 2026 · Updated Jul 18, 2026 · CVSS 7.5
A high-severity denial-of-service vulnerability (CVE-2026-9653) affects Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT communication modules due to improper validation of CIP Implicit Connection packets. A network-based attacker can send crafted packets to repeatedly disrupt device connections, though connections recover automatically. Rockwell Automation has released patches for the EN2 and EN3 modules, while the ENBT module is discontinued and will not receive a fix.
Technical Analysis
CVE-2026-9653 (CWE-354: Improper Validation of Integrity Check Value) stems from insufficient validation of CIP (Common Industrial Protocol) Implicit Connection packets processed by the affected communication modules. An unauthenticated attacker with network access can send specially crafted CIP packets to continuously disrupt device connections, resulting in a repeated denial-of-service condition, though the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) indicates no impact to confidentiality or integrity, only availability. The base score is 7.5 (CVSS 3.1) and 8.7 (CVSS 4.0), reflecting the low complexity and lack of required privileges or user interaction needed for exploitation. This is an OT/ICS-focused vulnerability with no direct AI agent system impact, though organizations running AI-driven industrial monitoring, predictive maintenance, or automation orchestration agents that depend on continuous connectivity to these communication modules could experience agent workflow disruptions or false alerting if device connections are repeatedly interrupted.
Affected Systems
Rockwell Automation 1756-EN3 (versions <=V12.001); Rockwell Automation 1756-EN2 (versions <=V12.001); Rockwell Automation 1756-ENBT (version V6.006)
Indicators of Compromise
- No specific IOCs published; exploitation involves crafted CIP Implicit Connection packets sent over network to affected communication modules
Remediation Steps
- 1
Update 1756-EN3 firmware
Update 1756-EN3 modules to version V12.002 or later as provided by Rockwell Automation.
- 2
Update 1756-EN2 firmware
Update 1756-EN2 modules to version V12.002 or later as provided by Rockwell Automation.
- 3
Mitigate unsupported 1756-ENBT devices
Since 1756-ENBT is discontinued with no available fix, plan for replacement with a supported communication module and apply network-level mitigations in the interim.
- 4
Network segmentation
Isolate control system networks and devices behind firewalls, separating them from business and internet-facing networks.
- 5
Restrict remote access
Use secure VPNs for any required remote access to control system networks, keeping VPN software updated.
- 6
Monitor and report
Monitor for anomalous CIP traffic and report suspected malicious activity to CISA for tracking and correlation.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.