8.7
CVE-2026-9653
- EPSS 0.18%
- Veröffentlicht 14.07.2026 15:00:06
- Zuletzt bearbeitet 14.07.2026 16:46:49
- CVE-Watchlists
- Unerledigt
1756-EN2, 1756-EN3, and 1756-ENBT - Denial of Service via CIP Connection ID
A denial-of-service security issue exists across all the 1756-EN2, EN3, and ENBT communication module due to improper validation of CIP Implicit Connection packets. An attacker on the network can exploit this by sending crafted packets to continuously disrupt device connections, though device connections will recover immediately after.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerRockwell Automation
≫
Produkt
1756-EN2, 1756-EN3
Default Statusunaffected
Version
12.001 and before
Status
affected
HerstellerRockwell Automation
≫
Produkt
1756-ENBT
Default Statusunaffected
Version
6.006
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.18% | 0.075 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| PSIRT@rockwellautomation.com | 8.7 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-354 Improper Validation of Integrity Check Value
The product does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.
https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1780.html