Status: UPDATED
| Advisory ID: CVE-2026-0646
Key Details
| CVE | CVE-2026-0646 |
| CVSS Score / Version | 8.7 (High) / CVSS v4.0 |
| Updated | 2026-06-17 |
| Affected products | Rockwell Automation FLEX I/O EtherNet/IP Adapters |
| Classified as | CWE-401 (Missing Release of Memory after Effective Lifetime) |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
A denial-of-service security issue exists within the 1794-AENTR adapter due to improper memory handling of CIP protocol requests. This vulnerability can result in the adapter faulting and losing connection to its associated I/O modules, requiring a manual reset to recover. (NVD)
What to Do
Monitor Rockwell Automation's web page for any future patch releases.
References