CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Rockwell Automation 1718-AENTR/1719-AENTR

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2935

As cited

Copy frozen at (site build).

vulnerabilities

Rockwell Automation 1718-AENTR/1719-AENTR

A denial-of-service vulnerability exists in Rockwell Automation 1718-AENTR and 1719-AENTR Ex I/O version 3.011, triggered by improper handling of UDP unicast network storms that causes device overload and communication loss, requiring a power cycle to recover. The vulnerability affects critical manufacturing infrastructure worldwide and carries a CVSS 3.1 score of 7.5 (HIGH). Rockwell Automation recommends upgrading to version 3.012 or later, with network isolation and access controls as mitigations for users unable to patch immediately.

Why it matters: Manufacturing operators running affected Rockwell Ex I/O modules should prioritize patching to 3.012 or later, as network-accessible devices lacking UDP rate limiting face immediate denial-of-service risk that could disrupt production lines without requiring authentication.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Rockwell Automation 1718-AENTR/1719-AENTR

Rockwell Automation released a security advisory for a denial-of-service vulnerability in the 1718-AENTR and 1719-AENTR industrial control system devices. CVE-2026-9140 stems from improper handling of UDP unicast network storms that overload the device and sever communications, requiring a power cycle to restore function. The vendor recommends upgrading to version 3.012 or later.

Why it matters: Industrial control system operators managing Rockwell Automation 1718/1719 Ex I/O devices version 3.011 face production downtime risk if attackers trigger network-based denial-of-service conditions; patching to version 3.012 or applying network segmentation mitigates the exposure.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Rockwell Automation 1718-AENTR/1719-AENTR

Rockwell Automation released a security advisory for a denial-of-service vulnerability in the 1718-AENTR and 1719-AENTR industrial control system devices. CVE-2026-9140 stems from improper handling of UDP unicast network storms that overload the device and sever communications, requiring a power cycle to restore function. The vendor recommends upgrading to version 3.012 or later.

Why it matters: Industrial control system operators managing Rockwell Automation 1718/1719 Ex I/O devices version 3.011 face production downtime risk if attackers trigger network-based denial-of-service conditions; patching to version 3.012 or applying network segmentation mitigates the exposure.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary