ctipilot.ch

Rockwell 1794-AENTR/AENTRXT FLEX I/O — unauthenticated web-interface password reset (CVSS 9.4)

cve · CVE-2026-0647

Coverage timeline
2
first 2026-06-18 → last 2026-06-22
Peak priority
high
1 high · 1 notable
Sources cited
3
2 hosts
Sections touched
2
trending-vulnerabilities, weekly-vuln-rollup
Co-occurring entities
3
see Related entities below
ATT&CK techniques
0
no mapped behavior yet

Story timeline

  1. 2026-06-22CVE-2026-0647 et al. — Rockwell Automation FLEX I/O unauthenticated password reset (9.4) and Logix CIP DoS, flagged by NCSC-CH
    weekly-vuln-rollup
  2. 2026-06-18CVE-2026-0647 et al. — Rockwell Automation FLEX I/O unauthenticated password reset (CVSS 9.4) and Logix CIP denial-of-service, flagged by NCSC-CH
    trending-vulnerabilities

Where this entity is cited

  • trending-vulnerabilities1
  • weekly-vuln-rollup1

Source distribution

  • cisa.gov2 (67%)
  • security-hub.ncsc.admin.ch1 (33%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Rockwell 1794-AENTR/AENTRXT FLEX I/O — unauthenticated web-interface password reset (CVSS 9.4) (2)

2026-06-22 · view entry permalink →

CVE-2026-0647 et al. — Rockwell Automation FLEX I/O unauthenticated password reset (9.4) and Logix CIP DoS, flagged by NCSC-CH

Rockwell disclosed five ICS CVEs on 2026-06-16, consolidated by NCSC-CH on 2026-06-17 and CISA ICS-CERT, headlined by an unauthenticated FLEX I/O password reset (CVE-2026-0647, 9.4) and Logix CIP denial-of-service flaws (CISA ICS-CERT ICSA-26-167-05; NCSC-CH Security Hub; daily 06-18). Directly relevant to Swiss/EU energy, water and manufacturing OT operators. Patch on the OT change-management cycle and verify these controllers are not reachable from IT networks.

vulnerability22 Jun 00:14Zmulti-sourceOpen finding ↗

2026-06-18 · view entry permalink →

CVE-2026-0647 et al. — Rockwell Automation FLEX I/O unauthenticated password reset (CVSS 9.4) and Logix CIP denial-of-service, flagged by NCSC-CH

Rockwell Automation disclosed five ICS CVEs on 2026-06-16, consolidated by NCSC-CH on 2026-06-17 (NCSC-CH Security Hub, 2026-06-17). CVE-2026-0647 (CVSS 9.4) lets an unauthenticated attacker reset the admin password on 1794-AENTR / 1794-AENTRXT FLEX I/O EtherNet/IP adapters (firmware ≤ V2.012) by sending a crafted HTTP GET to the adapter's embedded web server, enabling full takeover and I/O disruption (T0866) (CISA ICS-CERT, 2026-06-16). Companion CVE-2026-0646 (CVSS 7.5) is a CIP-handling DoS on the same adapter requiring a manual reset; CVE-2026-11317 (CVSS 7.5) causes a major non-recoverable fault on CompactLogix/ControlLogix 5370/5570 controllers via a crafted CIP message, requiring a full program download to recover (T0814) (CISA ICS-CERT, 2026-06-16); and CVE-2025-13036 (CVSS 7.7) is an authentication bypass in FactoryTalk Historian Site Edition. FLEX I/O fixes ship in firmware 2.013 (Rockwell SD1775); exploitation status is unknown for all. Where firmware cannot be applied immediately, restrict CIP and HTTP/HTTPS access to these devices to engineering workstations via OT segmentation.

vulnerability18 Jun 05:10Zmulti-sourceOpen finding ↗