Rockwell Automation 1756-ENBT Module

MonitorCVSS 7.5ICS-CERT ICSA-26-246-05Sep 3, 2026
Rockwell Automation
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

The 1756-ENBT Ethernet module contains a flaw (CWE-754: improper error handling) that allows remote attackers to crash the device by sending a malformed network packet. The module loses all network connectivity until manually restarted. All versions of the 1756-ENBT are affected. Rockwell Automation has not released a firmware patch for this module and recommends upgrading to replacement hardware (1756-EN2T or 1756-EN4TR) or implementing network security controls.

What this means
What could happen
An attacker can crash the 1756-ENBT module remotely, causing your control network to lose connectivity until the device is manually restarted. This disrupts communication between your PLCs and engineering workstations, halting automated processes.
Who's at risk
Water authorities, electric utilities, and any operator using Rockwell Automation's 1756-ENBT Ethernet modules for control network connectivity. This device typically bridges your automation network (PLCs, drives, sensors) to your engineering or monitoring network, making it critical for process operations.
How it could be exploited
An attacker on the network sends a specially crafted packet to the 1756-ENBT module's network interface. The module fails to handle the malformed input, crashes, and stops routing traffic between your control network segments. The device requires a manual reboot to restore operations.
Prerequisites
  • Network access to the 1756-ENBT module on its Ethernet port
  • No authentication required
Remotely exploitableNo authentication requiredLow complexityCauses denial of service (module crash)No patch available for existing hardware
Affected products (1)
ProductAffected VersionsFix Status
1756-ENBT moduleAll versionsNo fix yet
Remediation & Mitigation
0/3
Do now
0/1
WORKAROUNDRestrict network access to the 1756-ENBT module using firewall rules or network segmentation to block untrusted traffic
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXReplace 1756-ENBT modules with 1756-EN2T or 1756-EN4TR
Long-term hardening
0/1
HARDENINGImplement network segmentation to isolate your control network from untrusted zones
API: /api/v1/advisories/6b916d3c-b713-402f-9a61-6c14c6ab0a0e

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.