First published: Wed Sep 20 2023(Updated: )
A buffer overflow vulnerability exists in the Rockwell Automation select 1756-EN* communication devices. If exploited, a threat actor could potentially leverage this vulnerability to perform a remote code execution. To exploit this vulnerability, a threat actor would have to send a maliciously crafted CIP request to device.
Credit: PSIRT@rockwellautomation.com
Affected Software | Affected Version | How to fix |
---|---|---|
Rockwell Automation 1756-EN2T Series A Firmware | >=5.008<=5.028 | |
Rockwell Automation 1756-EN2T Series A | ||
Rockwell Automation 1756-EN2T Series B Firmware | >=5.008<=5.028 | |
Rockwell Automation 1756-EN2T Series B | ||
Rockwell Automation 1756-EN2T Series C Firmware | >=5.008<=5.028 | |
Rockwell Automation 1756-EN2T Series C | ||
Rockwell Automation 1756-EN2T Series D Firmware | <=11.002 | |
Rockwell Automation 1756-EN2T Series D Firmware | ||
Rockwell Automation 1756-EN2TK Series A Firmware | >=5.008<=5.028 | |
Rockwell Automation 1756-EN2TK Series A | ||
Rockwell Automation 1756-EN2TK Series B | >=5.008<=5.028 | |
Rockwell Automation 1756-EN2TK Series B | ||
Rockwell Automation 1756-EN2TK Series C Firmware | >=5.008<=5.028 | |
Rockwell Automation 1756-EN2TK Series C Firmware | ||
Rockwell Automation 1756-EN2TXT Series A Firmware | >=5.008<=5.028 | |
Rockwell Automation 1756-EN2TXT Series A Firmware | ||
Rockwell Automation 1756-EN2TXT Series B Firmware | >=5.008<=5.028 | |
Rockwell Automation 1756-EN2TXT Series B Firmware | ||
Rockwell Automation 1756-EN2TXT Series C Firmware | >=5.008<=5.028 | |
Rockwell Automation 1756-EN2TXT Series C Firmware | ||
Rockwell Automation 1756-EN2TXT Series D | <=11.002 | |
Rockwell Automation 1756-EN2TXT Series D | ||
Rockwell Automation 1756-EN2TP Series A Firmware | <=11.002 | |
Rockwell Automation 1756-EN2TP Series A | ||
Rockwell Automation 1756-EN2TPK Series A Firmware | <=11.002 | |
Rockwell Automation 1756-EN2TPK Series A Firmware | ||
Rockwell Automation 1756-EN2TR Series A Firmware | >=5.008<=5.028 | |
Rockwell Automation 1756-EN2TR Series A | ||
Rockwell Automation 1756-EN2TR Series B Firmware | >=5.008<=5.028 | |
Rockwell Automation 1756-EN2TR Series B Firmware | ||
Rockwell Automation 1756-EN2TR Series C Firmware | <=11.002 | |
Rockwell Automation 1756-EN2TR Series C | ||
Rockwell Automation 1756-EN3TRK Series A Firmware | >=5.008<=5.028 | |
Rockwell Automation 1756-EN2TRK Series A Firmware | ||
Rockwell Automation 1756-EN3TRK Series B Firmware | >=5.008<=5.028 | |
Rockwell Automation 1756-EN3TRK Series B | ||
Rockwell Automation 1756-EN2TRK Series C Firmware | <=11.002 | |
Rockwell Automation 1756-EN2TRK Series C Firmware | ||
Rockwell Automation 1756-EN2TRXT Series A Firmware | >=5.008<=5.028 | |
Rockwell Automation 1756-EN2TRXT Series A Firmware | ||
Rockwell Automation 1756-EN2TRXT Series B Firmware | >=5.008<=5.028 | |
Rockwell Automation 1756-EN2TRXT Series B | ||
Rockwell Automation 1756-EN2TRXT Series C | <=11.002 | |
Rockwell Automation 1756-EN2TRXT Series C | ||
Rockwell Automation 1756-EN2F Series A Firmware | >=5.008<=5.028 | |
Rockwell Automation 1756-EN2F Series A | ||
Rockwell Automation 1756-EN2F Series B Firmware | >=5.008<=5.028 | |
Rockwell Automation 1756-EN2F Series B Firmware | ||
Rockwell Automation 1756-EN2F Series C Firmware | <=11.002 | |
Rockwell Automation 1756-EN2F Series C | ||
Rockwell Automation 1756-EN2FK Series A Firmware | >=5.008<=5.028 | |
Rockwell Automation 1756-EN2FK Series A | ||
Rockwell Automation 1756-EN2FK Series B Firmware | >=5.008<=5.028 | |
Rockwell Automation 1756-EN2FK Series B | ||
Rockwell Automation 1756-EN2FK Series C Firmware | <=11.002 | |
Rockwell Automation 1756-EN2FK Series C | ||
Rockwell Automation 1756-EN3TR Series A Firmware | >=5.008<=5.028 | |
Rockwell Automation 1756-EN3TR Series A | ||
Rockwell Automation 1756-EN3TR Series B Firmware | <=11.003 | |
Rockwell Automation 1756-EN3TR Series B Firmware | ||
Rockwell Automation 1756-EN3TRK Series A Firmware | >=5.008<=5.028 | |
Rockwell Automation 1756-EN3TRK Series A | ||
Rockwell Automation 1756-EN3TRK Series B Firmware | <=11.002 | |
Rockwell Automation 1756-EN3TRK Series B Firmware | ||
rockwellautomation 1756-en2tpxt series A firmware | <=11.002 | |
rockwellautomation 1756-en2tpxt series A firmware |
Update firmware. Update EN2* ControlLogix communications modules to mitigated firmware. * Restrict traffic to the SMTP port (25), if not needed. * Customers using the EN2/EN3 versions 10.x and higher can disable the email object, if not needed. Instructions can be found in the EtherNet/IP Network Devices User Manual (rockwellautomation.com) https://literature.rockwellautomation.com/idc/groups/literature/documents/um/enet-um006_-en-p.pdf , publication ENET-UM006. * QA43240 - Recommended Security Guidelines from Rockwell Automation https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.