Rockwell Automation 1718-AENTR/1719-AENTR
Summary
CISA has alerted users to a denial-of-service vulnerability in Rockwell Automation 1718-AENTR/1719-AENTR devices, specifically version 3.011. Successful exploitation could lead to a denial-of-service condition caused by improper handling of UDP unicast network storms, requiring a power cycle to recover.
IFF Assessment
This vulnerability allows attackers to cause a denial-of-service condition, disrupting critical manufacturing operations.
Severity
The CVSS score of 7.5 (High) reflects the 'Allocation of Resources Without Limits or Throttling' vulnerability. This type of vulnerability often allows for denial-of-service attacks by overwhelming the system with requests, leading to unavailability.
Defender Context
This alert highlights a critical vulnerability in industrial control systems (ICS) that could lead to denial-of-service. Defenders in critical manufacturing sectors should prioritize patching or implementing mitigations for affected Rockwell Automation devices to prevent operational disruptions. This underscores the ongoing risks associated with legacy OT systems and the need for robust network segmentation and monitoring.