Rockwell Automation 1718-AENTR/1719-AENTR Denial-of-Service Vulnerability
Rockwell Automation's 1718-AENTR and 1719-AENTR devices have a vulnerability where a network storm can cause the device to stop working and require a physical restart.

English Brief
Rockwell Automation's 1718-AENTR and 1719-AENTR devices have a vulnerability where a network storm can cause the device to stop working and require a physical restart.
الموجز العربي
ثغرة حجب الخدمة في منتجات Rockwell Automation 1718-AENTR/1719-AENTR
تحتوي أجهزة Rockwell Automation 1718-AENTR و 1719-AENTR على ثغرة قد تؤدي إلى توقف الجهاز عن العمل عند تعرضه لتدفق مفاجئ في حركة مرور الشبكة، مما يتطلب إعادة تشغيله يدوياً.
- 1Audit all 1718-AENTR and 1719-AENTR devices to identify those running firmware version 3.011.
- 2Download firmware version 3.012 or later from the official Rockwell Automation support portal.
- 3Schedule a maintenance window to apply the firmware update.
English Advisory
// Intelligence Summary
A critical denial-of-service (DoS) vulnerability (CVE-2026-9140) exists in Rockwell Automation 1718-AENTR and 1719-AENTR modules, affecting firmware version 3.011. The vulnerability allows an attacker to cause the device to become unresponsive, requiring a manual power cycle to restore service. ### Technical Context
The issue is identified as an 'Allocation of Resources Without Limits or Throttling' (CWE-770). It is triggered by an improperly handled UDP unicast network storm, which overwhelms the device's resources. The CVSS 3.1 score is 7.5 (High). ### Exposure Notes
This vulnerability impacts users of 1718/1719 Ex I/O version 3.011. It is particularly concerning for organizations in the Critical Manufacturing sector relying on these components for industrial control system (ICS) communications. ### Defensive Priority
Organizations must prioritize upgrading affected devices to firmware version 3.012 or later. If immediate patching is not possible, network isolation and the implementation of traffic throttling and firewall rules are essential to prevent UDP unicast storms from reaching these assets.
التقرير العربي
// ملخص استخباراتي
توجد ثغرة أمنية تسبب حجب الخدمة (DoS) مصنفة تحت الرمز (CVE-2026-9140) في وحدات Rockwell Automation 1718-AENTR و 1719-AENTR، وتؤثر تحديداً على إصدار البرنامج الثابت 3.011. تتيح هذه الثغرة للمهاجم جعل الجهاز غير مستجيب، مما يتطلب إعادة تشغيل الجهاز يدوياً لاستعادة الخدمة. ### Technical Context
يُصنف الخلل تحت فئة 'تخصيص الموارد دون حدود أو تنظيم' (CWE-770). يتم تحفيز هذه الثغرة عند تعرض الجهاز لعاصفة شبكة (Network Storm) من نوع UDP unicast، مما يؤدي إلى استهلاك كامل لموارد الجهاز. تبلغ درجة خطورة الثغرة وفقاً لمعيار CVSS 3.1 مستوى 7.5 (مرتفع). ### Exposure Notes
تؤثر هذه الثغرة على مستخدمي إصدار 3.011 من أجهزة 1718/1719 Ex I/O. تعتبر هذه الثغرة حساسة بشكل خاص للمؤسسات في قطاع التصنيع الحيوي التي تعتمد على هذه المكونات في أنظمة التحكم الصناعية (ICS). ### Defensive Priority
يجب على المؤسسات إعطاء الأولوية القصوى لترقية الأجهزة المتأثرة إلى الإصدار 3.012 أو أحدث. في حال تعذر الترقية الفورية، يجب عزل الشبكة وتطبيق قواعد جدار حماية صارمة لمنع عواصف مرور UDP unicast من الوصول إلى هذه الأصول.
Mitigation Checklist
- 1Audit all 1718-AENTR and 1719-AENTR devices to identify those running firmware version 3.011.
- 2Download firmware version 3.012 or later from the official Rockwell Automation support portal.
- 3Schedule a maintenance window to apply the firmware update.
- 4Apply firewall rules to limit incoming UDP traffic to necessary communication partners only.
- 5Implement network segregation to isolate ICS components from business/corporate networks.
قائمة إجراءات التخفيف
- 1قم بفحص جميع أجهزة 1718-AENTR و 1719-AENTR لتحديد الأجهزة التي تعمل بإصدار البرنامج الثابت 3.011.
- 2قم بتنزيل إصدار البرنامج الثابت 3.012 أو أحدث من بوابة الدعم الرسمية لشركة Rockwell Automation.
- 3جدولة وقت صيانة لتطبيق تحديث البرنامج الثابت.
- 4تطبيق قواعد جدار حماية لتقييد حركة مرور UDP الواردة لتقتصر على الشركاء الضروريين فقط.
- 5تنفيذ عزل للشبكة لفصل مكونات أنظمة التحكم الصناعية (ICS) عن شبكات الأعمال والشبكات المؤسسية.
- Source: CISA Alerts
# Remediation Checklist for Rockwell Automation devices:
1. Audit all 1718-AENTR and 1719-AENTR devices to identify those running firmware version 3.011.
2. Download firmware version 3.012 or later from the official Rockwell Automation support portal.
3. Schedule a maintenance window to apply the firmware update.
4. Apply firewall rules to limit incoming UDP traffic to necessary communication partners only.
5. Implement network segregation to isolate ICS components from business/corporate networks.