cve-2025-8007

About this tag
CVE-2025-8007 is a denial-of-service vulnerability affecting Rockwell Automation 1756-series communication modules, including the 1756-ENT2R, 1756-EN4TR, and 1756-EN4TRXT. The flaw allows malformed or concurrent Forward Close messages to trigger a Major Non-Recoverable fault or crash, disrupting industrial control systems. Rockwell has released firmware version 7.001 to address the issue, and CISA has republished the advisory. This tag covers discussions about the vulnerability, affected hardware, patching guidance, and implications for ICS security.
  1. Rockwell 1756 EN Modules DoS Flaw - Patch to 7.001 (CVE-2025-8007/8008)

    Rockwell Automation has issued—and CISA has republished—an advisory warning that specific 1756-series communication modules can enter a Major Non‑Recoverable fault or crash when presented with malformed or concurrent Forward Close messages, creating a practical denial‑of‑service risk for...