VORANT. Threat Intelligence Sign in Get the full feed

Rockwell 1715-AENTR exposes unauthenticated debug port

high vulnerability energymanufacturinginfrastructure

A Rockwell Automation 1715-AENTR EtherNet/IP Adapter flaw exposes an unauthenticated debug CLI that could let attackers read/delete files or alter I/O states.

CISA has published an advisory for CVE-2026-10577 affecting Rockwell Automation's 1715-AENTR EtherNet/IP Adapter, versions 3.003 and earlier. The vulnerability stems from a network-accessible debug port that lacks proper authentication controls, allowing unauthenticated remote attackers to issue intrusive command-line interface commands against the device.

Successful exploitation could allow an attacker to read or delete files, stop running tasks, modify memory, and change I/O states, impacting confidentiality, integrity, and availability of the affected device. The product is deployed worldwide across energy, water/wastewater, and critical manufacturing sectors. Rockwell recommends upgrading to version 3.011 or later, and CISA has issued standard ICS network segmentation and access-control guidance. No known public exploitation has been reported at this time.

Mentioned in this report

Vulnerabilities CVE-2026-10577

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-04

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free