news.mlab.sh
Back to the feed
vulnerability

Rockwell Automation 1718-AENTR/1719-AENTR

High
Summary

Rockwell Automation has issued a security advisory regarding a denial-of-service vulnerability in its 1718-AENTR and 1719-AENTR products. Exploitation could lead to a denial-of-service condition, requiring a power cycle to recover. Rockwell Automation recommends upgrading to version 3.012 or later to address the issue.

Rockwell Automation has identified a critical denial-of-service vulnerability within its 1718-AENTR and 1719-AENTR products. This vulnerability stems from improper handling of a UDP unicast network storm, causing the device to become overloaded and lose communication. A power cycle is required to restore functionality. The issue is currently affecting devices worldwide, with Rockwell Automation’s headquarters located in the United States. Rockwell Automation recommends that users immediately upgrade to version 3.012 or later to mitigate the risk. CISA advises organizations to implement defensive measures, including minimizing network exposure, isolating control systems from business networks, and utilizing secure remote access methods like VPNs. Rockwell Automation has reported this vulnerability to CISA. The vulnerability is currently not being actively exploited publicly, but proactive mitigation is strongly recommended.

Read the full article at CISA Advisories