Rockwell Automation 1715-AENTR EtherNet/IP Adapter

Plan PatchCVSS 10ICS-CERT ICSA-26-195-04Jul 14, 2026
Rockwell Automation
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

A critical unauthenticated vulnerability in the 1715-AENTR EtherNet/IP Adapter (versions 3.003 and earlier) allows remote attackers to read or delete files, stop tasks, modify device memory, and change I/O states without authentication. The 1715 Redundant IO device has no patch available.

What this means
What could happen
An attacker can read or delete files, stop tasks, modify device memory, and change I/O states on the adapter, potentially halting production or corrupting data in your networked industrial devices.
Who's at risk
Water utilities and municipal electric utilities operating Rockwell Automation EtherNet/IP networked I/O adapters (1715-AENTR) in PLC-controlled processes, pump stations, or feeder/recloser equipment. Any facility using the 1715-AENTR for remote input/output control over Ethernet should prioritize this update.
How it could be exploited
An attacker with network access to the 1715-AENTR adapter can send specially crafted EtherNet/IP messages to trigger the vulnerability without authentication or user interaction, gaining the ability to execute arbitrary operations on the device.
Prerequisites
  • Network access to the EtherNet/IP port (typically port 44818) where the 1715-AENTR adapter is reachable
  • No credentials or authentication required
remotely exploitableno authentication requiredlow complexityhigh CVSS score (10.0)affects I/O control and device state
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (2)
1 with fix1 EOL
ProductAffected VersionsFix Status
1715-AENTR EtherNet/IP Adapter≤ 3.003Fix available
1715 Redundant IOAll versionsNo fix (EOL)
Remediation & Mitigation
0/3
Do now
0/1
WORKAROUNDRestrict network access to the 1715-AENTR adapter by implementing firewall rules to allow EtherNet/IP traffic only from authorized engineering and production systems
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

1715-AENTR EtherNet/IP Adapter
HOTFIXUpdate 1715-AENTR EtherNet/IP Adapter to version 3.011 or later
Mitigations - no patch available
0/1
1715 Redundant IO has reached End of Life. The vendor will not release a patch. Apply the following compensating controls:
HARDENINGIsolate 1715-AENTR adapters and 1715 Redundant IO devices on a dedicated industrial control network segment, separated from the corporate network and untrusted systems
API: /api/v1/advisories/ddd38f21-b6f4-4354-b455-91d63b226258

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.