CVE-2026-9653 Details
Description
A denial-of-service security issue exists across all the 1756-EN2, EN3, and ENBT communication module due to improper validation of CIP Implicit Connection packets. An attacker on the network can exploit this by sending crafted packets to continuously disrupt device connections, though device connections will recover immediately after.
A denial-of-service vulnerability has been identified in Rockwell Automation's 1756-EN2, EN3, and ENBT communication modules. This issue arises from improper validation of CIP Implicit Connection packets, allowing an attacker on the network to send crafted packets that disrupt device connections. Although the disruption is continuous, device connections recover immediately after the attack ceases.
Users of the 1756-EN2 and 1756-EN3 modules can upgrade to version 12.002 to address this vulnerability. For the 1756-ENBT module, which is discontinued and does not have a available fix, users should refer to Rockwell Automation's security best practices.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1780.html | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-354 | Improper Validation of Integrity Check Value | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | CVE Modified | CISA-ADP |
| Jul 14, 2026 | New CVE Received | [email protected] |