Rockwell Automation 1718-AENTR/1719-AENTR
MonitorCVSS 7.5ICS-CERT ICSA-26-202-08Jul 14, 2026
Rockwell Automation
Summary
The Rockwell 1718-AENTR and 1719-AENTR devices are vulnerable to a denial-of-service attack via network input. An attacker can craft a malicious network message that causes the device to become unresponsive, preventing normal operation until the device is manually restarted.
What this means
What could happen
An attacker can remotely crash the 1718-AENTR/1719-AENTR Ethernet adapter, forcing a manual restart and causing loss of network communication with connected control systems until the device recovers.
Who's at risk
This affects any facility using Rockwell Automation 1718-AENTR or 1719-AENTR Ethernet adapters in control networks. These devices are commonly used in manufacturing plants, water systems, and power distribution systems to enable Ethernet communication for PLCs and other industrial controllers. Loss of the adapter causes loss of network access to critical control equipment.
How it could be exploited
An attacker with network access to the Ethernet port of the 1718-AENTR or 1719-AENTR can send a specially crafted network packet that triggers a denial-of-service condition, causing the device to stop responding to legitimate traffic and requiring manual intervention to restore operation.
Prerequisites
- Network access to the Ethernet port of the 1718-AENTR or 1719-AENTR device
- No authentication required
remotely exploitableno authentication requiredno patch availableaffects control system communication
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (2)
1 with fix1 EOL
ProductAffected VersionsFix Status
1718-AENTR/1719-AENTRAll versionsNo fix (EOL)
1718/ 1719 Ex I/O: 3.0113.011Fix available
Remediation & Mitigation
0/4
Do now
0/21718-AENTR/1719-AENTR
HARDENINGImplement network segmentation or firewall rules to restrict access to the 1718-AENTR/1719-AENTR Ethernet ports to only authorized engineering workstations and control system networks
WORKAROUNDDeploy an inline network appliance or firewall rule to filter or validate incoming Ethernet traffic to the 1718-AENTR/1719-AENTR devices to block malformed or suspicious packets
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
1718-AENTR/1719-AENTR
HARDENINGMonitor the 1718-AENTR/1719-AENTR devices for unexpected restarts or loss of communication and establish a rapid response procedure to manually recover the devices if needed
Mitigations - no patch available
0/11718-AENTR/1719-AENTR has reached End of Life. The vendor will not release a patch. Apply the following compensating controls:
HARDENINGPlan for replacement of the 1718-AENTR/1719-AENTR with alternative Ethernet adapter solutions that provide DoS protection or have available patches
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/7b30d063-cc26-49a2-aca2-3eaf60a941edGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.