← Back to Feed

Rockwell Automation 1756-ENBT Module

CVE-2025-10478

September 3, 2026 · CISA (US-CERT) · Severity: CRITICAL

View CSAF Summary Successful exploitation of this vulnerability could crash the module. The device requires a restart to recover. The following versions of Rockwell Automation 1756-ENBT Module are affected: 1756-ENBT module vers:all/* (CVE-2025-10478) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation 1756-ENBT Module Improper Check for Unusual or Exceptional Conditions Background Critical Infrastructure Sectors: Critical Manufacturing, Food and Agriculture, Transportation Systems, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2025-10478 A denial-of-service security issue exists in the Rockwell Automation 1756-ENBT module which is a ControlLogix EtherNet/IP bridge that enables communication between Logix 5000 controllers and Ethernet devices. An attacker could exploit this vulnerability by sending a crafted CIP packet, causing the module to crash. The device requires a restart to recover. View CVE Details Affected Products Rockwell Automation 1756-ENBT Module Vendor:Rockwell Automation Product Version:Rockwell Automation 1756-ENBT module: vers:all/* Product Status:known_affected Remediations MitigationRockwell Automation recommends that users upgrade to 1756-EN2T or 1756-EN4TR. Users who are not able to upgrade should use Rockwell Automation's security best practices.https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight MitigationFor more information on this issue, see the corresponding Rockwell Automation security advisory.https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html Relevant CWE: CWE-754 Improper Check for Unusual or Exceptional Conditions Metrics CVSS Version Base Score Base Severity Vector...

Key Takeaways

  • CISA published an advisory for Rockwell Automation 1756-ENBT Module urging users to apply vendor patches and mitigations.
  • The advisory covers 1 vulnerabilities in Rockwell Automation 1756-ENBT Module that require immediate patching.
  • Active exploitation of vulnerabilities in Rockwell Automation 1756-ENBT Module has been reported, making patching urgent for affected organizations.
☕ Buy a Coffee