CVE-2025-10478 is a network-exploitable denial-of-service vulnerability in the Rockwell Automation 1756-ENBT EtherNet/IP bridge module. An unauthenticated attacker can send a crafted CIP packet to crash the device, which then requires a manual restart. All versions of the 1756-ENBT hardware are affected, and the vendor recommends replacing the module with a 1756-EN2T or 1756-EN4TR.
Rockwell Automation
10 posts
Rockwell Automation 1756-ENBT Module (CVE-2025-10478) Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix (CVE-2021-42260) A denial of service vulnerability (CVE-2021-42260) affects multiple Rockwell Automation industrial controllers. The flaw allows remote attackers to trigger an infinite loop via crafted data, causing a major nonrecoverable fault (MNRF) that requires a program download or stage 2 reset to recover. The CVSS v3.1 base score is 7.5 (High).
Rockwell Automation Historian ME (CVE-2025-12768, CVE-2026-12661) Rockwell Automation FactoryTalk Historian ME contains an out-of-bounds write vulnerability (CVE-2025-12768) and a stack-based buffer overflow vulnerability (CVE-2026-12661). CVE-2025-12768 permits remote code execution with low-level authentication. CVE-2026-12661 permits denial of service with high-level authentication. Both vulnerabilities affect Series B 5.202 and Series C 7.101.
Rockwell Automation RSLinx Classic (CVE-2026-9621, CVE-2026-9622, CVE-2026-9624 +1 more) Rockwell Automation RSLinx Classic versions 4.50 and earlier contain four network-exploitable denial-of-service vulnerabilities (CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625). These flaws stem from integer overflows, underflows, and buffer overflows in the handling of crafted CIP packets, allowing an unauthenticated remote attacker to crash the service. A fix is available in version 4.60.
Rockwell Automation OTTO Fleet Manager (CVE-2026-75112) Rockwell Automation OTTO Fleet Manager versions V2.36.2 and earlier use bcrypt with an insufficient work factor for password hashing. An attacker with access to an unencrypted system backup could perform offline brute-force attacks against stored password hashes at a reduced computational cost. The vulnerability is not remotely exploitable and requires adjacent network access and low privileges.
Rockwell Automation FLEX I/O EtherNet/IP Adapters (CVE-2026-0646, CVE-2026-0647) Rockwell Automation FLEX I/O EtherNet/IP Adapters version 2.012 are affected by two vulnerabilities. CVE-2026-0647 allows unauthenticated account takeover via the embedded web server, while CVE-2026-0646 enables a denial-of-service condition through malformed CIP protocol requests.
Rockwell Automation RSLinx (CVE-2020-13573) Rockwell Automation RSLinx Classic versions 4.50.00 and prior contain an out-of-bounds read and stack-based buffer overflow vulnerability (CVE-2020-13573). Successful exploitation by a remote attacker can lead to a denial of service condition where the application becomes unresponsive, or potentially allow for remote code execution.
Rockwell Automation Logix 5370 & 5570 Controllers Vulnerable To Denial of Service Via CIP (CVE-2026-11317) Rockwell Automation Logix 5370 and 5570 controllers are affected by a high-severity denial-of-service vulnerability (CVE-2026-11317, CVSS 8.7) triggered by crafted Common Industrial Protocol (CIP) messages. Successful exploitation results in a major nonrecoverable fault (MNRF) due to improper resource shutdown or release, requiring a manual program download to restore operations.
2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface The 2026 FIFA World Cup presents a massive, multi-jurisdictional attack surface threatened by state-nexus disruptive operations and financially motivated cybercrime. Key risks include Iran-aligned actors targeting municipal OT infrastructure, pro-Russian hacktivists launching high-volume DDoS attacks against tournament services, and cybercriminals deploying ransomware against the hospitality supply chain.
Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure Iranian-affiliated APT actors are actively targeting internet-exposed programmable logic controllers (PLCs), specifically Rockwell Automation devices, across multiple U.S. critical infrastructure sectors. The attackers utilize native configuration software and Dropbear SSH to manipulate project files and HMI displays, leading to operational disruptions and financial losses.