PT-2026-85371 · Rockwell Automation · 1756-Enbt
CVE-2025-10478
·
Published
2026-09-03
·
Updated
2026-09-04
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Rockwell Automation 1756-ENBT (affected versions not specified)
Description
A denial-of-service flaw exists in the 1756-ENBT module, which serves as an EtherNet/IP bridge for ControlLogix controllers. An attacker can crash the device by sending a crafted CIP (Common Industrial Protocol) packet, a communication protocol used in industrial automation. Recovery from this state requires a manual restart of the module. This issue has been exploited in real-world incidents to target critical infrastructure, including manufacturing and water treatment facilities.
Recommendations
Upgrade to 1756-EN2T or 1756-EN4TR modules.
Implement runtime segmentation to contain potential OT network compromises.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
1756-Enbt