Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT

Plan PatchCVSS 7.5ICS-CERT ICSA-26-197-02Jul 14, 2026
Rockwell Automation
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

The 1756-EN2, 1756-EN3, and 1756-ENBT Ethernet communication modules for Rockwell CompactLogix and ControlLogix PLCs contain a vulnerability in how they handle CIP (Common Industrial Protocol) connection identifiers. An attacker can send specially crafted packets with invalid connection IDs that cause the module to become unresponsive to all traffic. No fix is available from Rockwell for any version of these products.

What this means
What could happen
An attacker with network access to these Ethernet communication modules can send specially crafted packets that cause the device to stop responding, disrupting communication with PLCs and other devices on your industrial network until the module is manually reset.
Who's at risk
This affects any organization using Rockwell CompactLogix, ControlLogix, or other PLC systems that rely on 1756-EN2, 1756-EN3, or 1756-ENBT Ethernet modules for network communication. Water utilities, electric utilities, manufacturing facilities, and any industrial operation using Rockwell control systems should evaluate their use of these modules.
How it could be exploited
An attacker on the same network (or with access to your Ethernet infrastructure) sends malformed CIP (Common Industrial Protocol) packets with invalid connection IDs to the module's port. The device fails to validate or handle these packets correctly and enters a denial-of-service state where it stops responding to legitimate traffic.
Prerequisites
  • Network access to the Ethernet port of the affected module (port 2222 for CIP, or standard industrial protocols)
  • No authentication required; the vulnerability is in the packet parsing layer
remotely exploitableno authentication requiredlow complexityno patch availableaffects industrial communication infrastructure
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (4)
3 with fix1 EOL
ProductAffected VersionsFix Status
1756-EN2, 1756-EN3, and 1756-ENBTAll versionsNo fix (EOL)
1756-EN3≤ V12.00112.002
1756-EN2≤ V12.00112.002
1756-ENBT: V6.006V6.006Fix available
Remediation & Mitigation
0/3
Do now
0/1
WORKAROUNDRestrict network access to the Ethernet ports of these modules using a firewall or network segmentation. Allow only traffic from known engineering workstations and PLCs that need to communicate with these modules.
Mitigations - no patch available
0/2
1756-EN2, 1756-EN3, and 1756-ENBT has reached End of Life. The vendor will not release a patch. Apply the following compensating controls:
HARDENINGDisable unused CIP connections and services on the modules if your application does not require them.
HARDENINGMonitor network traffic to these modules for unexpected or malformed CIP packets. Alert on connection failures or unresponsive module status.
API: /api/v1/advisories/5631de0a-4958-4702-b975-d9c245190e99

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT | CVSS 7.5 - OTPulse