Rockwell 1756-ENBT module has no-patch DoS vulnerability
The module is discontinued, so the fix is a hardware swap, and operators in critical manufacturing, water, and transportation have to weigh replacement capex against availability risk on systems that may lack redundancy.
TL;DR
CISA published an advisory for CVE-2025-10478, a denial-of-service vulnerability affecting all versions of the Rockwell Automation 1756-ENBT EtherNet/IP bridge module. A single crafted CIP packet can remotely crash the device; recovery requires a physical restart. Rockwell has discontinued the 1756-ENBT and won't issue a patch. The recommended path is an upgrade to the 1756-EN2T or 1756-EN4TR, but no migration timeline, cost guidance, or compatibility verification process has been published for operators running legacy ControlLogix environments.
The 1756-ENBT is one of those modules that's been bolted into a rack for 15 years and nobody thinks about until it stops working. CVE-2025-10478 means an attacker can make it stop working with a single crafted CIP packet, no authentication, no user interaction, just a network path to the device. CVSS 4.0 puts it at 8.7 (High). CISA's advisory lists four critical-infrastructure sectors as affected: manufacturing, food and agriculture, transportation, and water.
The vulnerability is in the CIP Implicit Connection packet validation path. Rockwell's own advisory confirms the module is discontinued and no firmware fix is coming. That isn't unusual for end-of-life hardware, but it's worth noting that the 1756-ENBT has been the subject of CISA advisories going back to at least 2010, when an open debug port on UDP 17185 was flagged. This module has been in the field for decades, and it's still in active production use across the defense-industrial base.
Rockwell's mitigation guidance is straightforward: upgrade to the 1756-EN2T or 1756-EN4TR. For operators who can't upgrade immediately, the fallback is the standard ICS security best-practices menu, segment the network, restrict access, monitor. That's not nothing, but it's not a fix either. The attack surface is the CIP protocol itself, which is precisely what the module is supposed to be listening for. Network segmentation helps, but if the attacker is already on the OT side of the firewall, the module is still reachable.
What the advisory doesn't answer
Rockwell hasn't published a migration guide, a compatibility matrix, or a timeline for the recommended replacement path. Operators running legacy ControlLogix backplanes need to know whether the EN2T or EN4TR drops into their existing chassis without a firmware uplift on the controller side, whether the I/O configuration carries over, and whether the replacement introduces any timing changes that affect the process. None of that is in the advisory, and it's the information that determines whether the remediation is a weekend maintenance window or a multi-month capital project.
For the practitioner, the Monday-morning question is: do you have a cold spare on the shelf, or are you one packet away from a line-down event? If the answer is the latter, the network segmentation work starts now, and the capex conversation starts this quarter.
Published ·Deep Fathom