Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT
p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-197-02.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. /strong /p p The following versions of Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT are affected: /p ul li 1756-EN3 lt;=V12.001 (CVE-2026-9653) /li li 1756-EN2 lt;=V12.001 (CVE-2026-9653) /li li 1756-ENBT V6.006 (CVE-2026-9653) /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 7.5 /td td Rockwell Automation /td td Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT /td td Improper Validation of Integrity Check Value /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong United States /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2026-9653 /a /h3 div class="csaf-accordion-content" p A denial-of-service security issue exists across all the 1756-EN2, EN3, and ENBT communication module due to improper validation of CIP Implicit Connection packets. An attacker on the network can exploit this by sending crafted packets to continuously disrupt device connections, though device connections will recover immediately after. /p p a href="https://www.cve.org/CVERecord?id=CVE-2026-9653" View CVE Details /a /p hr h4 Affected Products /h4 h5 Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br Rockwell Automation /div div class="ics-version" strong Product Version: /strong br Rockwell Automation 1756-EN3: lt;=V12.001, Rockwell Automation 1756-EN2: lt;=V12.001, Rockwell Automation 1756-ENBT: V6.006 /div div class="ics-status" strong Product Status: /strong br known_affected /div /div div class="ics-remediations" h6 Remediations /h6 p strong Vendor fix /strong br Rockwell Automation recommends users take the following actions: 1756-EN3: Update to V12.002 /p p strong Vendor fix /strong br 1756-EN2: Update to V12.002 /p p strong Vendor fix /strong br 1756-ENBT: Product is discontinued, fix is unavailable /p /div p strong Relevant CWE: /strong a href="https://cwe.mitre.org/data/definitions/354.html" CWE-354 Improper Validation of Integrity Check Value /a /p hr h4 Metrics /h4 div class="csaf-table csaf-metrics-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-mi
Sign in to read the full article
Create a free account to access all news, downloads, and community features
Originally published by CISA
Source: https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-02
This article is shared for informational purposes. All rights belong to the original author and publisher. If you are the copyright holder and would like this content removed, please contact us.