Rockwell Automation 1756-ENBT Module
A denial-of-service vulnerability exists in Rockwell Automation's 1756-ENBT Module, a ControlLogix EtherNet/IP bridge. Exploitation could cause the module to crash, requiring a restart. Rockwell Automation recommends upgrading to alternative modules or implementing security best practices to mitigate the risk.
A denial-of-service security issue has been identified in Rockwell Automation's 1756-ENBT Module. This module, a ControlLogix EtherNet/IP bridge, facilitates communication between Logix 5000 controllers and Ethernet devices. An attacker could exploit this vulnerability by sending a crafted CIP packet, leading to a module crash and requiring a device restart to recover. The vulnerability affects all versions of the 1756-ENBT Module.
This issue is deployed worldwide, with Rockwell Automation's headquarters located in the United States. Rockwell Automation has reported this vulnerability to CISA.
The affected product is the Rockwell Automation 1756-ENBT Module. Rockwell Automation recommends that users upgrade to 1756-EN2T or 1756-EN4TR as a mitigation strategy. If upgrading is not possible, users should implement Rockwell Automation's security best practices.
CISA recommends organizations take defensive measures to minimize the risk of exploitation. These include minimizing network exposure for control system devices, isolating them from the internet, and using secure remote access methods like VPNs (while acknowledging VPN vulnerabilities). Organizations should also perform impact analysis and risk assessments before deploying defensive measures and report any suspected malicious activity to CISA.