All stories
highDefensive GuidanceCVE-2026-9140

UDP unicast network storms trigger denial-of-service in Rockwell Automation 1719-AENTR adapters

A high-severity denial-of-service vulnerability in Rockwell Automation's 1719-AENTR adapter can cause a complete loss of communication. An attacker triggering a UDP unicast network storm will overload the device, requiring a physical power cycle to restore operation. Implement network segmentation and traffic throttling to protect these critical industrial interfaces.

Summary

Rockwell Automation has disclosed a high-severity vulnerability affecting the 1719-AENTR EtherNet/IP adapter used in 1719 Ex I/O systems. The flaw, tracked as CVE-2026-9140, allows for a denial-of-service (DoS) condition that disrupts communication between the adapter and the control system. This issue was identified during internal routine testing by Rockwell Automation.

The vulnerability impacts devices used in hazardous location environments where distributed I/O communication is required via EtherNet/IP. Because the flaw results in a total loss of communication, recovery cannot be achieved through software alone; operators must physically power cycle the affected hardware to restore functionality.

Technical details

The security issue stems from how the 1719-AENTR handles specific network traffic patterns. Specifically, improper handling of a UDP unicast network storm causes the device to become overloaded. This behavior is categorized under CWE-770: Allocation of Resources Without Limits or Throttling.

When the adapter encounters this type of traffic, it loses its ability to maintain communication with the control system. The resulting state effectively removes the device from the network until a manual hardware reset occurs.

Affected products

The following Rockwell Automation products are impacted by CVE-2026-9140:

  • 1718-AENTR
  • 1719-AENTR (EtherNet/IP Adapter for 1719 Ex I/O system)

Defender guidance

Defenders should prioritize network-level controls to prevent the delivery of unmanaged UDP traffic to these adapters. Since the vulnerability is triggered by a UDP unicast network storm, limiting the volume and source of such traffic is critical.

Immediate actions include:

  • Enforce strict network segmentation to isolate I/O communication from general enterprise or untrusted networks.
  • Apply traffic throttling or rate-limiting on network switches to prevent unexpected bursts of UDP traffic from reaching the 1719-AENTR.
  • Monitor for unusual spikes in UDP unicast traffic directed toward industrial control system (ICS) assets.

If a device becomes unresponsive due to this vulnerability, a physical power cycle is required to recover communication.

Sources

  1. https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-08
  2. https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1778.html
Harith Dilshan

Harith Dilshan

- Offensive Security Engineer | Ethical Hacker | Penetration Tester -