IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Rockwell Automation 1756-ENBT Module

HIGH
CVSS 7.5
Date 2026-09-03T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of this vulnerability could crash the module. The device requires a restart to recover.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2025-10478 7.5 high
A denial-of-service security issue exists in the Rockwell Automation 1756-ENBT module which is a ControlLogix EtherNet/IP bridge that enables communication between Logix 5000 controllers and Ethernet devices. An attacker could exploit this vulnerability by sending a crafted CIP packet, causing the module to crash. The device requires a restart to recover.

// Remediations (2)

Mitigation: Rockwell Automation recommends that users upgrade to 1756-EN2T or 1756-EN4TR. Users who are not abl
Rockwell Automation recommends that users upgrade to 1756-EN2T or 1756-EN4TR. Users who are not able to upgrade should use Rockwell Automation's security best practices.
Mitigation: For more information on this issue, see the corresponding Rockwell Automation security advisory.
For more information on this issue, see the corresponding Rockwell Automation security advisory.

// References