# Rockwell Automation FLEX I/O Adapters Exposed to Remote Password Reset and Denial-of-Service Attacks


## The Threat


Rockwell Automation has released critical security advisories for its FLEX I/O EtherNet/IP Adapters, disclosing two vulnerabilities that expose industrial control systems to remote exploitation. The affected models—1794-AENTR and 1794-AENTRXT running firmware version 2.012—can be compromised by unauthenticated attackers over the network without any prior credentials or special knowledge of the target environment.


The first vulnerability (CVE-2026-0646) stems from improper memory handling in how the adapters process Common Industrial Protocol (CIP) requests. When a specially crafted CIP packet is sent to a vulnerable adapter, it triggers a memory leak that causes the device to fault and disconnect from its associated I/O modules. The adapter then enters a degraded state requiring manual administrator intervention to recover. This denial-of-service condition could disrupt production environments where FLEX I/O modules handle critical manufacturing processes.


More severe is the second vulnerability (CVE-2026-0647), which allows an unauthenticated attacker to change the device's embedded web server password by sending a malformed HTTP GET request to a specific endpoint. Because no authentication is required before password modification, any attacker with network access to the adapter can seize administrative control. Once compromised, an attacker gains the ability to modify device settings, reconfigure I/O mappings, or cause intentional outages. In manufacturing plants relying on these adapters for equipment control or safety systems, such unauthorized access represents a critical business and safety risk.


## Severity and Impact


| CVE | CVSS v3.1 | CVSS v4.0 | Vector (v3.1) | Attack Vector | Authentication |

|---------|---------------|---------------|-------------------|-------------------|--------------------|

| CVE-2026-0646 | 7.5 (HIGH) | 8.7 (HIGH) | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | Network | None Required |

| CVE-2026-0647 | 9.4 (CRITICAL) | 8.8 (HIGH) | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H | Network | None Required |


Affected Vulnerability Details:

  • CVE-2026-0646: Missing Release of Memory after Effective Lifetime (CWE-401) – Improper memory handling of CIP protocol requests
  • CVE-2026-0647: Missing Authentication for Critical Function (CWE-306) – Unauthenticated password reset via HTTP GET request

  • Both vulnerabilities are exploitable remotely without user interaction, and both require no prior authentication. The CVSS 9.4 score for CVE-2026-0647 places it in the critical range on version 3.1, reflecting the ease of exploitation and severity of impact.


    ## Affected Products


    Rockwell Automation FLEX I/O EtherNet/IP Adapters:

  • 1794-AENTR V2.012
  • 1794-AENTRXT V2.012

  • Both model variants running firmware version 2.012 are affected by both CVE-2026-0646 and CVE-2026-0647. These adapters are deployed globally in manufacturing, processing, and other critical infrastructure environments.


    ## Mitigations


    Immediate Actions:


    1. Apply Firmware Update: Rockwell Automation has released firmware version 2.013 to resolve both vulnerabilities. Organizations should prioritize deployment of this update to all affected adapters in their environment.


    2. Network Segmentation: Until patches can be applied, ensure FLEX I/O adapters are not directly accessible from untrusted networks or the internet. Deploy adapters behind firewalls and within isolated control system networks separated from business IT systems.


    3. Access Control: Restrict network access to the adapters' management interfaces to only authorized personnel and control systems. Use network segmentation and access control lists to limit connectivity to essential devices only.


    4. Monitor for Suspicious Activity: Watch for signs of exploitation, including:

    - Unexpected adapter resets or faults

    - Failed or successful login attempts to the web interface

    - Unexplained changes to device configuration

    - Unusual network traffic patterns directed at adapter management ports


    5. Compensating Controls: If immediate patching is not feasible, consider:

    - Running adapters in read-only mode where possible

    - Implementing network-based intrusion detection to identify malformed CIP packets

    - Reducing the scope of administrative privileges available through the embedded web server

    - Enabling connection logging and monitoring of adapter access


    6. VPN for Remote Access: If remote management of adapters is necessary, restrict all access through secure VPN channels with multi-factor authentication, never allowing direct internet exposure.


    Long-Term Actions:


  • Establish a regular firmware update schedule for all industrial control components
  • Conduct network assessments to identify all FLEX I/O adapters and document their current firmware versions
  • Implement change management procedures for any modifications to control system network architecture

  • ## References


  • Rockwell Automation Security Advisory: [https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1775.html](https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1775.html)
  • CISA Alert: Original notification and recommended practices
  • CVE-2026-0646: Improper memory handling in FLEX I/O EtherNet/IP Adapters
  • CVE-2026-0647: Missing authentication in FLEX I/O EtherNet/IP Adapter web interface

  • ---


    ## HackWire Analysis


    This pair of vulnerabilities illustrates a troubling pattern in industrial control systems: authentication mechanisms treated as afterthoughts rather than foundational security layers. The ability to reset a device password without any credentials is not merely a misconfiguration—it reflects a fundamental misunderstanding of what "protected" means in critical infrastructure contexts.


    CVE-2026-0647 is particularly alarming because it bypasses the first line of defense entirely. An attacker needs no credentials, no special tools, and no reverse engineering. A simple HTTP GET request is enough to seize administrative control of a device managing industrial processes. This is the kind of vulnerability that security researchers discover by accident while probing default endpoints, suggesting it may have existed undetected for years.


    The memory handling issue (CVE-2026-0646) carries different but equally serious implications. By triggering a controllable fault condition, attackers can weaponize denial-of-service against manufacturing environments where downtime translates directly into lost revenue. In facilities where FLEX I/O adapters manage safety-critical functions—such as conveyor control, machine interlocks, or emergency shutdown systems—a forced reset could create operational hazards alongside business disruption.


    The worldwide deployment of these adapters means the attack surface is large. Manufacturing plants, water treatment facilities, and other critical infrastructure operators running version 2.012 are all exposed. The good news: version 2.013 exists and addresses both issues. The bad news: patch deployment in industrial environments moves slowly. Many organizations will run version 2.012 for months or years after this advisory, making them persistent targets.


    Defenders should treat the update to 2.013 as urgent, not routine. Where immediate patching isn't possible, aggressive network segmentation and monitoring are non-negotiable. This isn't a vulnerability that favors defenders—every day an unpatched adapter remains network-accessible is a day an attacker could compromise it.


    — HackWire Editorial


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)