Rockwell Automation 1718-AENTR/1719-AENTR
View CSAF Summary Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product. The following versions of Rockwell Automation 1718-AENTR/1719-AENTR are affected: 1718/ 1719 Ex I/O 3.011 CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation 1718-AENTR/1719-AENTR Allocation of Resources Without Limits or Throttling Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-9140 A denial-of-service security issue exists in the 1719-AENTR. The security issue stems from improper handling of a UDP unicast network storm, which causes the device to become overloaded and lose communication. A power cycle is required to recover. View CVE Details Affected Products Rockwell Automation 1718-AENTR/1719-AENTR Vendor: Rockwell Automation Product Version: Rockwell Automation 1718/ 1719 Ex I/O: 3.011 Product Status: known_affected Remediations Vendor fix Rockwell Automation recommends users to upgrade to 1718/ 1719 Ex I/O version 3.012 or later. Mitigation Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices (https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight). https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight Mitigation For more information, see Rockwell Automation Security Advisories: https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html. https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html Relevant CWE: CWE-770 Allocation of Resources Without Limits or Throttling Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:
CSIRTS triage
- What
- A denial-of-service vulnerability exists due to improper handling of network storms.
- Who is affected
- Deployments of 1718-AENTR/1719-AENTR version 3.011.
- Urgency
- Critical remediation is necessary to prevent service disruption.
- Action
- Update to the latest version of 1718-AENTR/1719-AENTR.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch 1718-AENTR/1719-AENTR
Get an email when a new 1718-AENTR/1719-AENTR advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-08
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-91400.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-9140 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for Rockwell Automation
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- criticalRockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Modulecisa · 2026-07-30
- criticalRockwell Automation ThinManagercisa · 2026-07-23
- criticalRockwell Automation Studio 5000 Logix Designercisa · 2026-07-21
- criticalRockwell Automation 1734 POINT I/Ocisa · 2026-07-21
- criticalRockwell Automation FactoryTalk Services Platformcisa · 2026-07-21
- high[NEW] [high] Rockwell Automation CompactLogix and ControlLogix: Multiple vulnerabilitiescert-bund · 2026-07-17
More from CISA Cybersecurity Advisories
- criticalWatchfire Controller Software2026-07-30
- criticalMZ Automation GmbH libiec618502026-07-30
- criticalToptech Systems RCU II+ and Multiload II+2026-07-30
- criticalNASA Core Flight System (cFS) Health & Safety (HS) Application2026-07-30
- criticalMikroTik RouterOS2026-07-30