These flaws can do more than knock a box offline. On a plant floor, a faulting adapter can sever attached I/O modules and force a manual reset before service returns, so the standard patch-and-move-on response misses the recovery cost.
CISA says the affected devices are Rockwell FLEX I/O EtherNet/IP Adapters 1794-AENTR and 1794-AENTRXT at v2.012. CVE-2026-0646 can make the adapter fault from crafted CIP requests, and CVE-2026-0647 lets an unauthenticated attacker change the web password through a crafted HTTP GET request; Rockwell fixes both in 2.013.
The password flaw can hand over device administration, not just disrupt availability. In manufacturing environments that rely on these adapters for live I/O connectivity, that means the blast radius can extend beyond one interrupted unit to the control path around it.