highOther

Rockwell Automation 1756-EN2/EN3/ENBT CIP Implicit Connection Denial-of-Service Vulnerability

First seen Jul 18, 2026 · Updated Jul 18, 2026 · CVSS 7.5

ICSOTdenial-of-serviceCIPRockwell Automationindustrial-control-systemscritical-manufacturing

A high-severity denial-of-service vulnerability (CVE-2026-9653) affects Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT communication modules due to improper validation of CIP Implicit Connection packets. A network-based attacker can send crafted packets to repeatedly disrupt device connections, though connections recover automatically. Rockwell Automation has released patches for the EN2 and EN3 modules, while the ENBT module is discontinued and will not receive a fix.

Technical Analysis

CVE-2026-9653 (CWE-354: Improper Validation of Integrity Check Value) stems from insufficient validation of CIP (Common Industrial Protocol) Implicit Connection packets processed by the affected communication modules. An unauthenticated attacker with network access can send specially crafted CIP packets to continuously disrupt device connections, resulting in a repeated denial-of-service condition, though the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) indicates no impact to confidentiality or integrity, only availability. The base score is 7.5 (CVSS 3.1) and 8.7 (CVSS 4.0), reflecting the low complexity and lack of required privileges or user interaction needed for exploitation. This is an OT/ICS-focused vulnerability with no direct AI agent system impact, though organizations running AI-driven industrial monitoring, predictive maintenance, or automation orchestration agents that depend on continuous connectivity to these communication modules could experience agent workflow disruptions or false alerting if device connections are repeatedly interrupted.

Affected Systems

Rockwell Automation 1756-EN3 (versions <=V12.001); Rockwell Automation 1756-EN2 (versions <=V12.001); Rockwell Automation 1756-ENBT (version V6.006)

Indicators of Compromise

  • No specific IOCs published; exploitation involves crafted CIP Implicit Connection packets sent over network to affected communication modules

Remediation Steps

  1. 1

    Update 1756-EN3 firmware

    Update 1756-EN3 modules to version V12.002 or later as provided by Rockwell Automation.

  2. 2

    Update 1756-EN2 firmware

    Update 1756-EN2 modules to version V12.002 or later as provided by Rockwell Automation.

  3. 3

    Mitigate unsupported 1756-ENBT devices

    Since 1756-ENBT is discontinued with no available fix, plan for replacement with a supported communication module and apply network-level mitigations in the interim.

  4. 4

    Network segmentation

    Isolate control system networks and devices behind firewalls, separating them from business and internet-facing networks.

  5. 5

    Restrict remote access

    Use secure VPNs for any required remote access to control system networks, keeping VPN software updated.

  6. 6

    Monitor and report

    Monitor for anomalous CIP traffic and report suspected malicious activity to CISA for tracking and correlation.

CVE / Advisory IDs

CVE-2026-9653

Industries Most Exposed

Critical ManufacturingIndustrial Control SystemsOperational Technology

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.