Rockwell 1756-ENBT Module DoS Flaw Disclosed
A crafted CIP packet can crash Rockwell Automation's 1756-ENBT EtherNet/IP module, requiring a manual restart to recover.
CISA published an ICS advisory detailing CVE-2025-10478, a denial-of-service vulnerability affecting all versions of Rockwell Automation's 1756-ENBT module, a ControlLogix EtherNet/IP bridge used to connect Logix 5000 controllers to Ethernet devices. An attacker who can send a specially crafted CIP packet to the module can cause it to crash, requiring a physical restart to restore operations. No authentication bypass, code execution, or data exposure is described—the impact is limited to availability loss on the affected module.
The vulnerability is classified under CWE-754 (Improper Check for Unusual or Exceptional Conditions) and affects deployments across critical manufacturing, food and agriculture, transportation systems, and water/wastewater sectors worldwide. Rockwell Automation reported the issue to CISA and recommends organizations upgrade to the 1756-EN2T or 1756-EN4TR modules, which are not affected. Users unable to upgrade should apply Rockwell's general security best practices for ControlLogix deployments.
CISA states no known public exploitation of this vulnerability has been reported at this time. Standard ICS network hardening guidance applies: isolate control system networks from business networks and the internet, place devices behind firewalls, and use VPNs with up-to-date patching for any required remote access.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-05
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free