Rockwell Automation 1756-ENBT Module Denial-of-Service Vulnerability
First seen Sep 4, 2026 · Updated Sep 4, 2026 · CVSS 7.5
A high-severity denial-of-service vulnerability (CVE-2025-10478) affects all versions of the Rockwell Automation 1756-ENBT ControlLogix EtherNet/IP bridge module. An attacker can send a crafted CIP packet to crash the module, requiring a manual restart to restore functionality, potentially disrupting industrial communications in critical infrastructure environments.
Technical Analysis
CVE-2025-10478 is a CWE-754 (Improper Check for Unusual or Exceptional Conditions) flaw in the 1756-ENBT module's handling of CIP (Common Industrial Protocol) packets. A remote, unauthenticated attacker can send a specially crafted CIP packet over the network to trigger a crash of the module, resulting in a denial-of-service condition that halts EtherNet/IP communication between Logix 5000 controllers and connected devices until manually restarted. The vulnerability carries a CVSS v3.1 score of 7.5 (High) and CVSS v4.0 score of 8.7 (High), reflecting network-based, low-complexity exploitation with no privileges or user interaction required, though impact is limited to availability with no confidentiality or integrity loss. This is a legacy OT/ICS networking module vulnerability with no direct AI agent system impact, as it affects industrial communication hardware rather than IT infrastructure, software supply chains, or credential/API-key exposure paths relevant to agent frameworks.
Affected Systems
Rockwell Automation 1756-ENBT ControlLogix EtherNet/IP bridge module, all firmware/software versions (vers:all/*)
Indicators of Compromise
- No specific IOCs provided; no known public exploitation reported by CISA at this time.
Remediation Steps
- 1
Upgrade Hardware
Migrate from the 1756-ENBT module to the 1756-EN2T or 1756-EN4TR modules, which are not affected by this vulnerability.
- 2
Apply Vendor Security Best Practices
For devices that cannot be upgraded, implement Rockwell Automation's published security best practices referenced in their support advisory.
- 3
Network Segmentation
Isolate control system networks and remote devices behind firewalls, separating them from business IT networks and the public internet.
- 4
Restrict Remote Access
Where remote access is required, use up-to-date VPN solutions and ensure connected devices are also secured, as VPNs are only as secure as their endpoints.
- 5
Monitor and Report
Monitor for anomalous CIP traffic and unexpected module restarts; report suspected malicious activity to CISA per internal incident response procedures.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.