CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Rockwell Automation 1715-AENTR EtherNet/IP Adapter

criticalCVE-2026-10577
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to read or delete files, stop tasks, modify memory, and change I/O states, potentially impacting the confidentiality, integrity, and availability of the device. The following versions of Rockwell Automation 1715-AENTR EtherNet/IP Adapter are affected: 1715-AENTR EtherNet/IP Adapter <=3.003 (CVE-2026-10577) CVSS Vendor Equipment Vulnerabilities v3 10 Rockwell Automation Rockwell Automation 1715-AENTR EtherNet/IP Adapter Missing Authentication for Critical Function Background Critical Infrastructure Sectors: Energy, Water and Wastewater, Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-10577 A security issue exists within the 1715-AENTR EtherNet/IP Adapter. The affected product exposes a network-accessible debug port that does not enforce proper privilege controls, allowing unauthenticated remote access to intrusive command-line interface (CLI) commands. If exploited, a threat actor could read or delete files, stop tasks, modify memory, and change I/O states, potentially impacting the confidentiality, integrity, and availability of the device. View CVE Details Affected Products Rockwell Automation 1715-AENTR EtherNet/IP Adapter Vendor: Rockwell Automation Product Version: Rockwell Automation 1715-AENTR EtherNet/IP Adapter: <=3.003 Product Status: known_affected Remediations Vendor fix Rockwell Automation recommends that users update to 1715-AENTR EtherNet/IP Adapter version 3.011 and later. Mitigation Rockwell Automation recommends users of the affected software who are not able to upgrade to one of the corrected versions should use their security best practices. https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight Mitigation For more information, see the Rockwell Automation security advisory SD1785 https://www.rockwellautomation.com/en-us/trust-

CSIRTS triage

What
A missing authentication vulnerability could allow unauthorized access to critical functions.
Who is affected
Users of Rockwell Automation 1715-AENTR EtherNet/IP Adapter versions up to 3.003.
Urgency
Remediation is urgent due to the critical nature of the vulnerability.
Action
Update to a version above 3.003.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch 1715-AENTR EtherNet/IP Adapter

Get an email when a new 1715-AENTR EtherNet/IP Adapter advisory drops — max one per day, one-click unsubscribe.

Details

Source
CISA Cybersecurity Advisories (US · national-cert · site)
Severity
critical
Published
2026-07-14
Exploitation
Not in CISA KEV at last sync

Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-04

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-10577coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for Rockwell Automation

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from CISA Cybersecurity Advisories