Back to all lessons
Awareness Lessons
last month

Rockwell Automation EtherNet/IP Module Vulnerable to Denial-of-Service Attack

A denial-of-service vulnerability (CVE-2025-10478) in Rockwell Automation's 1756-ENBT ControlLogix EtherNet/IP bridge module allows attackers to crash the module, disrupting industrial control system communications and requiring manual intervention to recover. This is particularly dangerous in operational technology (OT) environments where module availability is critical to continuous industrial processes. The fact that the primary mitigation is upgrading to a newer module — rather than a simple patch — highlights how legacy industrial hardware often cannot be easily remediated, making network-level controls essential. Unpatched OT devices exposed to network access represent a significant risk to industrial safety, uptime, and operational continuity.

Tactical Insight

Immediate actions

  • Upgrade affected 1756-ENBT modules to Rockwell Automation's recommended newer hardware versions as soon as operationally feasible.
  • Apply Rockwell Automation's published security best practices as interim mitigations if immediate hardware replacement is not possible.
  • Audit network exposure of all ControlLogix EtherNet/IP bridge modules to determine which are reachable from untrusted network segments.

Long-term improvements

  • Maintain a comprehensive, up-to-date inventory of all OT/ICS hardware including firmware and end-of-support status to accelerate vulnerability response.
  • Establish a formal lifecycle management process for industrial control hardware to proactively replace end-of-life modules before vulnerabilities are publicly disclosed.
  • Implement a vendor security advisory monitoring program to receive timely notifications for all critical infrastructure components.

Detection & containment measures

  • Enforce strict network segmentation by isolating EtherNet/IP modules behind industrial DMZs, restricting access to only authorized engineering workstations.
  • Deploy OT-aware intrusion detection systems (IDS) capable of monitoring EtherNet/IP traffic for anomalous or malformed packets that could trigger the vulnerability.
  • Establish alerting and incident response runbooks specifically for module crash events to minimize recovery time and operational impact.