1756-EN2, 1756-EN3, and 1756-ENBT - Denial of Service via CIP Connection ID 漏洞概述 CVE ID: CVE-2026-9653 CVSS 3.1 Base Score: 7.5/10 CVSS 4.0 Base Score: 8.7/10 CWE: CWE-354 Improper Validation of Integrity Check Value Known Exploited Vulnerability: No 影响范围 Affected Product: 1756-EN3, 1756-EN2, 1756-ENBT Affected Firmware Version: V12.001 and before, V6.006 Corrected in Firmware Version: V12.002, Product is discontinued, fix is unavailable 修复方案 Mitigations and Workarounds: Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use our security best practices. 漏洞详情 A denial-of-service security issue exists across all the 1756-EN2, EN3, and ENBT communication module due to improper validation of CIP Implicit Connection packets. An attacker on the network can exploit this by sending crafted packets to continuously disrupt device connections, though device connections will recover immediately after. 参考链接 Vulnerability Exploitability Exchange Rockwell Automation security advisories Rockwell Automation Home Trust Center 法律免责声明 ROCKWELL AUTOMATION DOES NOT WARRANT THE COMPLETENESS, TIMELINESS OR ACCURACY OF ANY OF THE DATA CONTAINED IN THIS WEB SITE AND MAY MAKE CHANGES THERETO AT ANY TIME IN ITS SOLE DISCRETION WITHOUT NOTICE. FURTHER, ALL INFORMATION CONVEYED HEREBY IS PROVIDED TO USERS "AS IS." IN NO EVENT SHALL ROCKWELL BE LIABLE FOR ANY DAMAGES OF ANY KIND INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS PROFIT OR DAMAGE, EVEN IF ROCKWELL AUTOMATION HAVE BEEN ADVISED ON THE POSSIBILITY OF SUCH DAMAGES. ROCKWELL AUTOMATION DISCLAIMS ALL WARRANTIES WHETHER EXPRESSED OR IMPLIED IN RESPECT OF THE INFORMATION (INCLUDING SOFTWARE) PROVIDED HEREBY, INCLUDING THE IMPLIED WARRANTIES OF FITNESS FOR A PARTICULAR PURPOSE, MERCHANTABILITY, AND NON-INFRINGEMENT. Note that certain jurisdictions do not countenance the exclusion of implied warranties; thus, this disclaimer may not apply to you. Copyright ©2022 Rockwell Automation, Inc.