---
schema: 1
kind: vulnerability
title: "CVE-2026-0647 et al. — Rockwell Automation FLEX I/O unauthenticated password reset (CVSS 9.4) and Logix CIP denial-of-service, flagged by NCSC-CH"
headline: "CVE-2026-0647 et al. — Rockwell Automation FLEX I/O unauthenticated password reset (CVSS 9.4) and Logix CIP denial-of-service, flagged by NCSC-CH"
summary: "Rockwell FLEX I/O adapters: unauthenticated web-interface password reset (CVE-2026-0647, CVSS 9.4), flagged by NCSC-CH. A crafted HTTP GET resets the admin password on 1794-AENTR/AENTRXT EtherNet/IP adapters; companion CVEs crash Logix controllers via malformed CIP (CISA ICS-CERT, 2026-06-16). Fixed in firmware 2.013; segment OT now."
discovered_at: "2026-06-18T05:10:32Z"
event_date: 2026-06-17
run_id: 2026-06-18-aa7ee817
priority: high
immediate_action: null
tags:
  - ot-ics
  - vulnerabilities
  - auth-bypass
  - dos
  - pre-auth
  - patch-available
regions:
  - global
  - europe
sectors:
  - energy
  - manufacturing
  - water
entities: []
cves:
  - id: CVE-2026-0647
    cvss: "9.4"
    epss: null
    type: auth-bypass
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
  - id: CVE-2026-0646
    cvss: "7.5"
    epss: null
    type: auth-bypass
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
  - id: CVE-2026-11317
    cvss: "7.5"
    epss: null
    type: auth-bypass
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
  - id: CVE-2025-13036
    cvss: "7.7"
    epss: null
    type: auth-bypass
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
sources:
  - url: "https://www.cisa.gov/news-events/ics-advisories/icsa-26-167-05"
    publisher: CISA ICS-CERT ICSA-26-167-05
    role: primary
  - url: "https://security-hub.ncsc.admin.ch/#/posts/12639"
    publisher: NCSC-CH Security Hub
    role: corroborating
  - url: "https://www.cisa.gov/news-events/ics-advisories/icsa-26-167-03"
    publisher: CISA ICS-CERT ICSA-26-167-03
    role: corroborating
closed_sources: []
evidence: []
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions:
  - "**Upgrade Rockwell FLEX I/O adapters to firmware 2.013 and segment OT** (§ 2). For CVE-2026-0647 and the Logix CIP DoS CVEs, restrict CIP and HTTP/HTTPS to engineering workstations until firmware is applied."
migrated_from: briefs/2026-06-18.md
---

Rockwell Automation disclosed five ICS CVEs on 2026-06-16, consolidated by NCSC-CH on 2026-06-17 ([NCSC-CH Security Hub, 2026-06-17](https://security-hub.ncsc.admin.ch/#/posts/12639)). **CVE-2026-0647** (CVSS 9.4) lets an unauthenticated attacker reset the admin password on 1794-AENTR / 1794-AENTRXT FLEX I/O EtherNet/IP adapters (firmware ≤ V2.012) by sending a crafted HTTP GET to the adapter's embedded web server, enabling full takeover and I/O disruption (`T0866`) ([CISA ICS-CERT, 2026-06-16](https://www.cisa.gov/news-events/ics-advisories/icsa-26-167-05)). Companion **CVE-2026-0646** (CVSS 7.5) is a CIP-handling DoS on the same adapter requiring a manual reset; **CVE-2026-11317** (CVSS 7.5) causes a major non-recoverable fault on CompactLogix/ControlLogix 5370/5570 controllers via a crafted CIP message, requiring a full program download to recover (`T0814`) ([CISA ICS-CERT, 2026-06-16](https://www.cisa.gov/news-events/ics-advisories/icsa-26-167-03)); and **CVE-2025-13036** (CVSS 7.7) is an authentication bypass in FactoryTalk Historian Site Edition. FLEX I/O fixes ship in firmware 2.013 (Rockwell SD1775); exploitation status is unknown for all. Where firmware cannot be applied immediately, restrict CIP and HTTP/HTTPS access to these devices to engineering workstations via OT segmentation.
