Crafted CIP packets trigger denial-of-service and halt industrial I/O on Rockwell Flex 5000 adapters
Sending crafted CIP packets to a FLEX 5000 EtherNet/IP adapter can trigger a denial-of-service state that halts industrial I/O. Recovery requires a physical power cycle of the module. If you manage these adapters, prioritize network segmentation to block unauthorized CIP traffic.
Summary
A high-severity vulnerability in Rockwell Automation's FLEX 5000 EtherNet/IP Adapters allows an attacker to disrupt industrial automation processes by sending specially crafted Common Industrial Protocol (CIP) packets. The flaw results in a denial-of-service condition that halts the module and its associated I/O. Because the device becomes unresponsive, manual intervention via a power cycle is required to restore operation.
Technical details
The vulnerability, identified as CVE-2026-12659, stems from improper handling of exceptional conditions during the processing of CIP communication. These adapters serve as high-performance distributed I/O links that connect FLEX 5000 I/O modules to EtherNet/IP networks, often supporting advanced topologies like Device Level Ring (DLR).
When an adapter receives a crafted packet that triggers these unhandled exceptions, the module ceases normal functioning. This disruption extends to all associated I/O connected to that specific adapter.
Affected products
The vulnerability impacts several FLEX 5000 EtherNet/IP Adapter models:
| Model |
|---|
| 5094-AENTR |
| 5094-AENTRXT |
| 5094-AEN2TR |
| 5094-AEN2TRXT |
| 5094-AENSFPR |
| 5094-AENSFPRXT |
| 5094-AEN2SFPR |
| 5094-AEN2SFPRXT |
Why this matters for defenders
The primary risk is operational downtime. Because the module requires a physical power cycle to recover, remote remediation is not possible once the denial-of-service state is triggered. In an industrial environment, this could mean halting production lines or losing control over critical I/O points until a technician can reach the hardware.
Since the vulnerability is triggered via CIP packets sent over the network, any actor with network access to the adapter's IP address can potentially execute this attack.
Defender guidance
To mitigate the risk of CVE-2026-12659, focus on controlling access to the industrial network:
- Network Segmentation: Ensure that EtherNet/IP networks are isolated from broader corporate or external networks. Use firewalls to restrict CIP traffic only to known, authorized controllers and devices.
- Access Control: Implement strict rules to prevent unauthorized devices from communicating with the FLEX 5000 adapters.
- Monitor CIP Traffic: Watch for unusual or malformed industrial protocol traffic that could indicate an attempt to exploit exceptional conditions in the adapter's processing logic.
For more specific technical details and official advisories, refer to the Rockwell Automation Trust Center: https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1789.html
