highOther

Rockwell Automation 1756-ENBT Module Denial-of-Service Vulnerability

First seen Sep 4, 2026 · Updated Sep 4, 2026 · CVSS 7.5

ICSOTdenial-of-serviceCIP-protocolRockwell-AutomationEtherNet-IPindustrial-control-systemsCISA-advisory

A high-severity denial-of-service vulnerability (CVE-2025-10478) affects all versions of the Rockwell Automation 1756-ENBT ControlLogix EtherNet/IP bridge module. An attacker can send a crafted CIP packet to crash the module, requiring a manual restart to restore functionality, potentially disrupting industrial communications in critical infrastructure environments.

Technical Analysis

CVE-2025-10478 is a CWE-754 (Improper Check for Unusual or Exceptional Conditions) flaw in the 1756-ENBT module's handling of CIP (Common Industrial Protocol) packets. A remote, unauthenticated attacker can send a specially crafted CIP packet over the network to trigger a crash of the module, resulting in a denial-of-service condition that halts EtherNet/IP communication between Logix 5000 controllers and connected devices until manually restarted. The vulnerability carries a CVSS v3.1 score of 7.5 (High) and CVSS v4.0 score of 8.7 (High), reflecting network-based, low-complexity exploitation with no privileges or user interaction required, though impact is limited to availability with no confidentiality or integrity loss. This is a legacy OT/ICS networking module vulnerability with no direct AI agent system impact, as it affects industrial communication hardware rather than IT infrastructure, software supply chains, or credential/API-key exposure paths relevant to agent frameworks.

Affected Systems

Rockwell Automation 1756-ENBT ControlLogix EtherNet/IP bridge module, all firmware/software versions (vers:all/*)

Indicators of Compromise

  • No specific IOCs provided; no known public exploitation reported by CISA at this time.

Remediation Steps

  1. 1

    Upgrade Hardware

    Migrate from the 1756-ENBT module to the 1756-EN2T or 1756-EN4TR modules, which are not affected by this vulnerability.

  2. 2

    Apply Vendor Security Best Practices

    For devices that cannot be upgraded, implement Rockwell Automation's published security best practices referenced in their support advisory.

  3. 3

    Network Segmentation

    Isolate control system networks and remote devices behind firewalls, separating them from business IT networks and the public internet.

  4. 4

    Restrict Remote Access

    Where remote access is required, use up-to-date VPN solutions and ensure connected devices are also secured, as VPNs are only as secure as their endpoints.

  5. 5

    Monitor and Report

    Monitor for anomalous CIP traffic and unexpected module restarts; report suspected malicious activity to CISA per internal incident response procedures.

CVE / Advisory IDs

CVE-2025-10478

Industries Most Exposed

Critical ManufacturingFood and AgricultureTransportation SystemsWater and Wastewater

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.