Tec Nikan
فارسی
Talk to us
All news

A ControlLogix Bridge Gets a Crash Bug and No Firmware Fix

Rockwell's SD1798 lists every version of the 1756-ENBT as affected and the corrected firmware as not available. The remedy is a new module — and three of the nine advisories never reached CISA's feed.

OT securityRockwell AutomationControlLogixvulnerability managementlegacy equipment

Rockwell Automation published nine security advisories on 1 September 2026, numbered SD1792 through SD1800 — three more than CISA carried the same day. The one worth reading in full is SD1798.

It covers CVE-2026-84235 in the 1756-ENBT, the EtherNet/IP bridge that connects Logix 5000 controllers to Ethernet devices, and it is rated CVSS v3.1 7.5 and CVSS v4.0 8.7. A crafted CIP packet crashes the module, which then needs a restart to recover. Affected catalogue numbers are listed as 1756-ENBT, 1756-EWEB and L3xX.

The two fields that matter are the ones most advisories fill in routinely. Under affected versions: all versions. Under corrected firmware: not available. Rockwell marks the advisory Corrected: No, Workaround: Yes, and the stated solution is to upgrade the hardware — replace the module with a 1756-EN2T or 1756-EN4TR. The issue was reported by an external source during routine testing, and revision 1.0 was issued on 1 September.

That turns a security advisory into a capital expenditure. The 1756-ENBT sits in a great many legacy ControlLogix racks, and a module swap is not a firmware push: it means scheduling downtime, re-addressing, re-testing the communication paths and, on validated processes, re-qualifying them. For sites that cannot do that quickly, the workaround is the usual one — make sure nothing untrusted can put a CIP packet in front of that module.

Two of the other eight are worth noting. SD1797 covers ArmorStart LT distributed motor controllers, bulletins 290E, 291E and 294E at firmware v2.001 and below: CVE-2026-19471 is a stored cross-site scripting flaw and CVE-2026-19472 is a denial of service triggered by a crafted HTTP PUT to the embedded web server, rated 7.5 and 8.7 on CVSS v4.0. Both are fixed in v2.002. SD1793 covers ControlFLASH V15.07 and prior, where the installer grants the Everyone group write permission on the ControlFLASH\0001 directory — arbitrary code execution at the logged-in user's privilege level, fixed in 15.08, with a manual workaround for sites that cannot upgrade: open the folder's properties, edit the Security tab, remove the Everyone group.

SD1793, SD1797 and SD1798 have no counterpart in CISA's 1 September batch. A vulnerability management process that consumes only the government feed missed all three, including the one with no fix. Vendor PSIRT feeds are not a nice-to-have supplement to the ICS advisories; on this evidence they are the more complete source.

Source: Rockwell Automation

Want to work with us?

Tell us what you're building and we'll help you scope the first deployment.