ics-otregulatorNewsThe Broadside1 min read

CISA flags CVSS 10 Rockwell EtherNet/IP adapter takeover flaw

This is the bad OT advisory: network access, no credentials, no user interaction, and commands that can change I/O states.


TL;DR

CISA republished Rockwell Automation advisory SD1785 for CVE-2026-10577, a CVSS 10.0 flaw in 1715-AENTR EtherNet/IP Adapter versions 3.003 and earlier. The exposed debug port allows unauthenticated remote access to intrusive CLI commands, including file deletion, task termination, memory modification, and I/O state changes. Energy, water, critical manufacturing, and contractors or MSPs supporting those environments should upgrade to version 3.011 or reduce network exposure immediately. CISA says it has no reports of public exploitation.

CISA’s advisory on CVE-2026-10577 is short, but the operational point is not subtle. Rockwell Automation 1715-AENTR EtherNet/IP Adapter versions 3.003 and earlier expose a network-accessible debug port without proper privilege controls. The CVSS score is 10.0 under both CVSS 3.1 and 4.0, with network attack, low complexity, no privileges, and no user interaction. That is about as clean an exploitation path as an OT defender wants never to see.

The affected device sits in the usual places where “just patch it” becomes a planning meeting: energy, water and wastewater, and critical manufacturing, deployed worldwide. Successful exploitation could let an attacker read or delete files, stop tasks, modify memory, and change I/O states. For compliance teams, assessors, defense-industrial-base suppliers, and managed service providers supporting those environments, this is not mainly a paperwork finding. It is a present remote-takeover risk on a control-system component.

Rockwell’s fixed line is 1715-AENTR version 3.011 and later. For organizations that cannot upgrade immediately, CISA’s mitigation language is the familiar ICS baseline: minimize network exposure, keep control-system devices off the public internet, put control networks and remote devices behind firewalls, isolate them from business networks, and keep VPNs current when remote access is required. That advice reduces attack surface, but it does not make the missing-authentication bug disappear.

The practical move is to inventory 1715-AENTR adapters, confirm firmware, and treat any version 3.003 or earlier that is reachable from routable networks as an urgent remediation item. CISA says it has no known public exploitation reports for this CVE. That is useful, but with an unauthenticated debug interface and CVSS 10.0, “not yet reported” is not a maintenance window strategy.


Published ·Deep Fathom