Rockwell 1756-ENBT Denial of Service Vulnerability

MonitorCVSS 7.5SD1798Sep 1, 2026
Rockwell Automation
Summary

The Rockwell Automation 1756-ENBT Ethernet module is vulnerable to a denial of service attack when it receives a specially crafted network packet. The module will crash, severing network connectivity for the attached PLC. No firmware update is available from the vendor. Devices remain vulnerable regardless of software version.

What this means
What could happen
An attacker could crash the 1756-ENBT Ethernet module, causing a complete loss of network communication for any CompactLogix or ControlLogix PLC connected to it. This would stop all remote monitoring and control operations until the module is manually rebooted.
Who's at risk
Water utilities and municipal power systems using Rockwell CompactLogix or ControlLogix PLCs with 1756-ENBT Ethernet modules for remote monitoring, SCADA integration, or engineering access. Any facility that depends on network connectivity to control pumps, motors, valve actuators, or other critical process equipment.
How it could be exploited
An attacker with network access to the 1756-ENBT module could send a specially crafted network packet that causes the Ethernet module to crash. Since the module handles all network traffic for the PLC, loss of the module takes the entire controller offline.
Prerequisites
  • Network access to the 1756-ENBT module on your network
  • No authentication required
Remotely exploitableNo authentication requiredNo patch availableCauses loss of network communications to critical control system
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (1)
ProductAffected VersionsFix Status
1756-ENBT Denial ofAll versionsNo fix (EOL)
Remediation & Mitigation
0/3
Do now
0/1
HARDENINGIsolate the 1756-ENBT module and PLC to a dedicated industrial control network segment using a firewall. Restrict inbound traffic to only the IP addresses and ports required for your legitimate engineering and SCADA systems.
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HARDENINGImplement network monitoring and alerting rules to detect unusual traffic patterns directed at your 1756-ENBT modules (e.g., unexpected connection attempts or malformed packets).
Long-term hardening
0/1
WORKAROUNDImplement an inline network appliance or host-based protection that can validate and sanitize network traffic to the 1756-ENBT before it reaches the module.
API: /api/v1/advisories/fc2358fc-1706-4a08-992e-58040090c2ee

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Rockwell 1756-ENBT Denial of Service Vulnerability | CVSS 7.5 - OTPulse