CVE-2026-84235
Received Received - Intake

Denial of Service in Rockwell Automation Product via CIP Packet

Vulnerability report for CVE-2026-84235, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: Rockwell Automation

Description

A denial-of-service security issue exists in the affected product. The security issue stems from a crafted CIP packet being sent crashing the module. The device requires a restart to recover.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-01
AI Q&A
2026-09-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
rockwell_automation 1756_enbt *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a denial-of-service issue in a Rockwell Automation product. It is triggered by sending a specially crafted CIP packet to the device, causing it to crash. The device then requires a manual restart to recover normal operation.

Detection Guidance

Monitor network traffic for unusual CIP packets targeting the 1756-ENBT module. Check for module crashes requiring manual restarts. Use network monitoring tools to detect abnormal EtherNet/IP communication patterns.

Impact Analysis

The vulnerability can disrupt the availability of the affected device by crashing it, leading to downtime. This may impact industrial processes relying on the device, causing operational delays or requiring manual intervention to restart the system.

Compliance Impact

This vulnerability could impact compliance with standards like GDPR and HIPAA by causing system unavailability due to denial-of-service attacks. Downtime may disrupt data processing or access, potentially violating availability requirements in these regulations.

Mitigation Strategies

Upgrade affected modules to 1756-EN2T or 1756-EN4TR as recommended. If unable to upgrade, implement strict network segmentation and access controls to limit exposure to crafted CIP packets.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84235. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart