Rockwell Automation disclosed two vulnerabilities, CVE-2023-3595 and CVE-2023-3596, affecting select ControlLogix EtherNet/IP communication modules in the 1756-EN2, 1756-EN3, and 1756-EN4 series. The flaws in the devices’ Common Industrial Protocol implementation could allow remote code execution with persistence on EN2 and EN3 modules and denial-of-service attacks on EN4 modules, creating risks that include loss of control, loss of view, theft of operational data, and disruptive or destructive process manipulation in industrial environments.
Dragos said the exploit capability was linked to an unnamed APT actor, though it had not observed exploitation in the wild at the time of reporting and did not know the intended victims or sectors. Rockwell issued patches, including for some out-of-support hardware, and recommended firmware upgrades, restricting CIP-related ports, network segmentation, optional disabling of the CIP Socket Object, and monitoring for anomalous CIP traffic, firmware changes, and memory writes as part of broader ICS defensive controls.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Dragos said that as of mid-July 2023 it had no evidence that the exploit capability tied to an unnamed APT actor had been used in the wild. It also said the intended victims and targeted sectors were unknown at that time.
Rockwell Automation provided patches for all affected products, including some out-of-support hardware, and also released detection rules. Guidance included firmware upgrades, restricting CIP-related ports, network segmentation, optional disabling of the CIP Socket Object, and monitoring for anomalous CIP activity and firmware changes.
Rockwell Automation disclosed CVE-2023-3595 and CVE-2023-3596 affecting select ControlLogix EtherNet/IP communication modules in the 1756-EN2, 1756-EN3, and 1756-EN4 series. The flaws in the Common Industrial Protocol implementation can enable remote code execution with persistence on EN2/EN3 modules and denial-of-service attacks on EN4 modules.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.