Tec Nikan
فارسی
Talk to us
All news

A ControlLogix Module With No Patch Coming

One crafted CIP packet crashes every version of Rockwell's 1756-ENBT, and recovery needs a manual restart. The vendor's remedy is a different module, which makes this a capital decision.

ICS advisoriesRockwellControlLogixvulnerabilitieslegacy equipment

CISA published advisory ICSA-26-246-05 on 3 September covering Rockwell Automation's 1756-ENBT communications module. The vulnerability, CVE-2025-10478, is classified CWE-754 — improper check for unusual or exceptional conditions — and scores 7.5 on CVSS v3.1 and 8.7 on v4.0. The vector is network-reachable, low complexity, no privileges and no user interaction, with availability the only impact.

The mechanism is simple and the consequence is not. An attacker sends a crafted CIP packet, the module crashes, and it requires a restart to recover. There is no automatic recovery. On a ControlLogix rack, that means a communications module going dark until someone physically attends to it, which in a running process is the definition of an unplanned outage.

What separates this from an ordinary advisory is the affected-version line: all versions. There is no fixed firmware, and Rockwell's mitigation is to migrate to the 1756-EN2T or 1756-EN4TR modules, alongside firewall isolation and removing internet accessibility. That converts a patch-cycle item into a capital-planning item. The 1756-ENBT has been in service for a long time and sits in a great many legacy racks; replacing one is not a download but a hardware change, with the outage window, the configuration transfer and the re-validation that implies.

Which makes segmentation the near-term answer for most sites rather than a supporting recommendation. If the module cannot be fixed and cannot immediately be replaced, then the control is entirely about what can reach it. This is the case the zone-and-conduit exercise exists for: a device with a known, unauthenticated denial-of-service path is exactly the asset whose reachable set should be enumerated and reduced to the connections the process actually needs.

The advisory lists Critical Manufacturing, Food and Agriculture, Transportation Systems, and Water and Wastewater as affected sectors. Rockwell self-reported the vulnerability to CISA, and no public exploitation had been reported at the time of release.

Worth noting for anyone tracking their own exposure: this was one of ten ICS advisories CISA published on the same day. A single advisory is a task; ten in one release is a reminder that the inventory question — which of these products do we actually run, and where — is the part most organisations cannot answer quickly.

Source: CISA

Want to work with us?

Tell us what you're building and we'll help you scope the first deployment.