Rockwell Automation 1715-AENTR EtherNet/IP Adapter
Rockwell Automation’s 1715-AENTR EtherNet/IP Adapter is vulnerable to a security flaw that could allow unauthorized remote access to a debug port, potentially leading to file deletion, task stopping, memory modification, and I/O state changes. Users are advised to update to version 3.011 or later to mitigate the risk. This impacts critical infrastructure sectors like energy and manufacturing.
A security issue exists within the Rockwell Automation 1715-AENTR EtherNet/IP Adapter. The affected product exposes a network-accessible debug port that does not enforce proper privilege controls, allowing unauthenticated remote access to intrusive command-line interface (CLI) commands. If exploited, a threat actor could read or delete files, stop tasks, modify memory, and change I/O states, potentially impacting the confidentiality, integrity, and availability of the device.
The following versions of Rockwell Automation 1715-AENTR EtherNet/IP Adapter are affected:
- 1715-AENTR EtherNet/IP Adapter <=3.003 (CVE-2026-10577)
Background: This vulnerability is critical for sectors like energy, water and wastewater, and critical manufacturing. The vulnerability was reported to CISA by Rockwell Automation.
Affected Products: Rockwell Automation 1715-AENTR EtherNet/IP Adapter
Remediation: Rockwell Automation recommends that users update to 1715-AENTR EtherNet/IP Adapter version 3.011 and later.
CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.