Rockwell Automation 1756-ENBT Module

Summary

A denial-of-service vulnerability (CVE-2025-10478) has been identified in Rockwell Automation's 1756-ENBT module. Exploitation of this flaw could lead to a module crash, requiring a restart for recovery. The vulnerability is related to an "Improper Check for Unusual or Exceptional Conditions."

IFF Assessment

FOE

This vulnerability allows for a denial-of-service attack, which negatively impacts the availability of critical industrial control systems.

Severity

7.5 High

The CVSS score of 7.5 indicates a High severity. This is likely due to the potential for the module to crash, impacting operational availability, and the fact that it requires a manual restart, suggesting a significant disruption.

Defender Context

This vulnerability affects critical infrastructure sectors, highlighting the need for diligent patching and monitoring of industrial control systems. Defenders should be aware of potential denial-of-service attacks targeting Rockwell Automation 1756-ENBT modules and consider implementing mitigations such as upgrading to newer hardware or following vendor-recommended security practices.

Read Full Story →