Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT
Rockwell Automation has released a vulnerability in its 1756-EN2, 1756-EN3, and 1756-ENBT communication modules. Exploitation could lead to a denial-of-service condition. Users are advised to update to the latest versions, with a fix unavailable for the 1756-ENBT due to its discontinuation. CISA recommends minimizing network exposure and utilizing secure remote access methods.
A denial-of-service security issue exists across Rockwell Automation’s 1756-EN2, 1756-EN3, and 1756-ENBT communication modules. This vulnerability stems from improper validation of CIP Implicit Connection packets, allowing an attacker to continuously disrupt device connections. While device connections will recover immediately, the potential for disruption is a concern. The affected products are: Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT. Specifically, the 1756-ENBT is discontinued and therefore lacks a fix. Rockwell Automation recommends users update to the latest versions: 1756-EN3: Update to V12.002, 1756-EN2: Update to V12.002. CISA advises organizations to minimize network exposure for all control system devices, isolating them behind firewalls and from business networks. Secure remote access should be implemented using VPNs, recognizing that VPNs themselves can have vulnerabilities. Organizations are encouraged to perform impact analysis and risk assessments and to implement recommended cybersecurity strategies for proactive defense of ICS assets. CISA also recommends vigilance against social engineering attacks and reporting of suspected malicious activity.