As cited
Copy frozen at (site build).
vulnerabilities
Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT
Rockwell Automation disclosed a denial-of-service vulnerability (CVE-2026-9653) affecting communication modules 1756-EN2, 1756-EN3, and 1756-ENBT used in critical manufacturing environments worldwide. The flaw stems from improper validation of CIP Implicit Connection packets, allowing network-based attackers to send crafted packets that temporarily disrupt device connections. Patches are available for the EN2 and EN3 modules (version 12.002), though the ENBT module is discontinued with no fix available.
Why it matters: Manufacturing and critical infrastructure operators deploying these Rockwell Automation modules face service disruption risk if exposed to the public internet or untrusted networks; immediate patching of EN2 and EN3 devices and network segmentation of ENBT modules are required to prevent availability attacks.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT
Rockwell Automation disclosed a denial-of-service vulnerability (CVE-2026-9653) affecting communication modules 1756-EN2, 1756-EN3, and 1756-ENBT used in critical manufacturing environments worldwide. The flaw stems from improper validation of CIP Implicit Connection packets, allowing network-based attackers to send crafted packets that temporarily disrupt device connections. Patches are available for the EN2 and EN3 modules (version 12.002), though the ENBT module is discontinued with no fix available.
Why it matters: Manufacturing and critical infrastructure operators deploying these Rockwell Automation modules face service disruption risk if exposed to the public internet or untrusted networks; immediate patching of EN2 and EN3 devices and network segmentation of ENBT modules are required to prevent availability attacks.
- Source published
- First seen by Cybersecurity Tracker