CVE-2026-0646: Rockwell Automation FLEX I/O Dual-port EtherNet/IP Adapters – Multiple Vulnerabilities
A denial-of-service security issue exists within the 1794-AENTR adapter due to improper memory handling of CIP protocol requests. This vulnerability can result in the adapter faulting and losing connection to its associated I/O modules, requiring a manual reset to recover.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Operational
If the 1794-AENTR adapter faults and loses connection to its I/O modules due to the described CIP request memory-handling issue, perform a manual reset of the adapter to recover operation.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0646?
The severity of CVE-2026-0646 is rated as high, with a score of 8.7.
How do I fix CVE-2026-0646?
To mitigate CVE-2026-0646, ensure that the firmware of the Rockwell Automation 1794-AENTR FLEX I/O Dual-port EtherNet/IP Adapter is updated to the latest version.
What type of vulnerability is CVE-2026-0646?
CVE-2026-0646 is a denial-of-service vulnerability affecting the 1794-AENTR adapter due to improper memory handling of CIP protocol requests.
What are the consequences of exploiting CVE-2026-0646?
Exploiting CVE-2026-0646 can cause the adapter to fault and lose connection to its I/O modules, necessitating a manual reset to restore functionality.
Which product is impacted by CVE-2026-0646?
CVE-2026-0646 impacts the Rockwell Automation 1794-AENTR FLEX I/O Dual-port EtherNet/IP Adapter.