This release includes security enhancements as a part of our ongoing efforts to improve security. For information regarding Rockwell Automation's vulnerability disclosure process, please reference the Rockwell Automation Vulnerability Policy.
Improved Product Resiliency for Firmware Revision 12.001
Product improvements have been made to increase product resiliency to potentially disruptive activities. These enhancements have been verified not to affect product safety, performance, expected life, configuration, or operation of the product. Rockwell Automation recommends that you follow good Industrial Control System (ICS) security practices that include regular product updates. To maintain authenticity, obtain product updates and new releases directly from Rockwell Automation.
This release includes the following system features.
Product Resiliency Improvement
System Feature Identified as of:
This release includes enhancements that are intended to improve product resiliency to potentially disruptive activities. These enhancements do not affect product safety, performance, expected life, configuration, or operation of the product. Rockwell Automation advises customers to follow good Industrial Control System (ICS®) security practices that include regular product updates. To be sure of authenticity, obtain product updates and new releases directly from Rockwell Automation.
Improved Messaging Performance
System Feature Identified as of:
With these modules, message performance has been improved over earlier versions.
This release corrects the following anomalies.
Corrected: Revision 10.010
When you install RSLinx® Classic software, the EDS files for these modules are not necessarily available. You can use RSLinx Classic software to upload EDS files from the module or download EDS files from the Product Compatibility and Download Center website, http://www.rockwellautomation.com/global/support/pcdc.page.
Corrected: Revision 10.010
You can get an error if you use a MSG instruction to send emails through the module when communicating with a SMTP server. If an error occurs, the error string that is reported in the MSG instruction is missing the first four characters.
Safety Overwhelm (Lgx00153887)
Corrected: Revision 10.010
CE 4003835992 and 4003810669 UB -- 1756-EN2T/D overwhelms 1734-AENT/A with safety.
Leading Zero in IP Address (Lgx00173828)
Corrected: Revision 10.010
The 1756-EN2T/D, 1756-EN2TR/C, and 1756-EN2F/Cmodules accept a leading zero in the IP address.
Controller Connection Drop Issues
Corrected: Revision 10.010
The CompactLogix® 5370 L3 controllers do not reestablish connections to 1756-EN2T/D modules, but they do reestablish connections with the 1756-EN2T/A modules.
The Compact GuardLogix® 5370 controllers drop connections to the 1756-EN2TR module during remote I/O rack power cycling.
The CompactLogix 5370 L3 controllers do not reestablish connections in a DLR configuration.
The Compact GuardLogix 5370 controllers experience a #0204 Connection Timeout to the 1756-EN2F module after a cable break.
Connection drop between controller and 1756 Ethernet module during cable break
Corrected Anomaly with Firmware Revision 10.010
Known Anomaly First Identified as of Firmware Revision 10.007
Catalog Numbers:
Following a cable break and reconnection of the CompactLogix™ 5370 controller, it cannot communicate with the 1756 Ethernet module (Lgx00210701). Workaround is to cycle power or manually disconnect and reconnect the controller to re-establish communication.
This release has the following known anomalies.
USB Port Cannot be Disabled Using a CIP Generic MSG Instruction (1356346)
|
Communication Modules
|
First Known in Firmware Revision
|
Corrected in Firmware Revision
|
|
1756-EN2T/D
|
10.010
|
12.001 and later
|
|
1756-EN2TR/C
|
10.010
|
12.001 and later
|
|
1756-EN3TR/B
|
10.010
|
12.001 and later
|
|
1756-EN2F/C
|
10.010
|
12.001 and later
|
|
1756-EN2TP/A
|
10.020
|
12.001 and later
|
USB port cannot be disabled using a CIP™ Generic MSG Instruction.
These anomalies are from previous releases but are still known in this release.
Known Anomaly Identified as of:
When a Cisco switch with IP Device Tracking enabled (Cisco IOS firmware that is released after August 2013) is used within the layer 2 broadcast domain, the following can occur:
For more information, see Tech Note 568750. The Tech Note is available at https://rockwellautomation.custhelp.com/app/answers/detail/a_id/568750. A separate login is required.
By default, Stratix™ Ethernet switches do not exhibit this behavior.
Not Valid Device Error
Known Anomaly Identified as of:
In the Studio 5000 Logix Designer® application, a Not Valid Device error can occur. This error occurs when you change the module type from one of the previously listed modules to any of the other listed modules in the Change Type dialog box.
|
Device
|
First Known in
Firmware Revision
|
Corrected in Firmware Revision
|
|
CompactLogix® 5380
|
28.011
|
34.014, 35.013, 36.011 and later
|
|
Compact GuardLogix® 5380 SIL 2
|
31.011
|
34.014, 35.013, 36.011 and later
|
|
Compact GuardLogix 5380 SIL 3
|
32.013
|
34.014, 35.013, 36.011 and later
|
|
CompactLogix 5380 Process
|
33.011
|
34.014, 35.013, 36.011 and later
|
|
CompactLogix 5480
|
32.011
|
34.014, 35.013, 36.011 and later
|
|
ControlLogix® 5580
|
28.011
|
34.014, 35.013, 36.011 and later
|
|
GuardLogix 5580
|
31.011
|
34.014, 35.013, 36.011 and later
|
|
ControlLogix 5580 Process
|
33.011
|
34.014, 35.013, 36.011 and later
|
|
1756-EN4TR
|
2.001
|
6.001 and later
|
|
1756-EN3TR/B, 1756-EN2TR/C
|
10.007
|
12.001 and later
|
|
1756-EN2TP
|
10.020
|
12.001 and later
|
|
1756-EN2T/D
|
10.006
|
12.001 and later
|
|
1756-EN2F/C
|
10.009
|
12.001 and later
|
|
Module
|
First Known in
Firmware Revision
|
Corrected in
Firmware Revision
|
|
1756-EN4TR, 1756-EN4TRXT
|
4.001
|
8.011 and later
|
|
1756-EN2T, 1756-EN2TXT, 1756-EN2TR
|
2.007
|
—
|
CPU Utilization Error (00179391)
Corrected Anomaly with Firmware Revision 11.001
Known Anomaly First Identified in Catalog Numbers:
When accessing Web pages, CPU utilization is 100%.
Increased ICMP message per second capacity (00191724)
Corrected Anomaly with Firmware Revision 11.001
Known Anomaly First Identified in Catalog Numbers:
ICMP message per second capacity increased.
Ethernet module sends incorrect ARP at switchover (00194847)
Corrected Anomaly with Firmware Revision 11.001
Known Anomaly First Identified in Catalog Numbers:
Ethernet module sends Address Resolution Protocol (ARP) to gateway address with source IP 0.0.0.0 at ControlLogix Redundancy switchover.
Rack-optimized Connections Can Cause an Ethernet Module to Assert (1186272, 1186282, 942336)
|
Communication Modules
|
First Known in Firmware Revision
|
Corrected in Firmware Revision
|
|
1756-EN2T, 1756-EN2TR
|
10.007
|
12.001 and later
|
|
1756-EN3TR
|
10.007
|
12.001 and later
|
|
1756-EN4TR,
1756-EN4TRK,
1756-EN4TRXT |
2.001
|
4.001
|
Five or more rack-optimized connections that are targeted to an Ethernet module cause the module to assert immediately. The module status display shows ‘RackInput.cpp LineXXX’ information in the assert message.
GoAhead Web Server Vulnerabilities – EtherNet/IP Communication Devices (1693483)
|
Product
|
First Known in Firmware Revision
|
Corrected in Firmware Revision
|
|
1747-AENTR
|
2.002
|
--
|
|
1769-AENTR
|
1.001
|
1.003 and later
|
|
1756-EN2T/D
|
10.006
|
11.002 and later
|
|
1756-EN2TR/C
|
10.007
|
11.002 and later
|
|
1756-EN2TSC/B (discontinued)
|
10.01
|
--
|
|
5069-AEN2TR (discontinued)
|
3.011
|
--
|
|
Product
|
First Known in Firmware Revision
|
Corrected in Firmware Revision
|
|
1747-AENTR
|
2.002
|
--
|
|
1769-AENTR
|
1.001
|
1.003 and later
|
|
1756-EN2F/C
|
11.001
|
11.002 and later
|
|
1756-EN2T/D
|
11.001
|
11.002 and later
|
|
1756-EN2TP
|
11.001
|
11.002 and later
|
|
1756-EN2TR/C
|
11.001
|
11.002 and later
|
|
1756-EN2TSC/B (discontinued)
|
10.01
|
--
|
|
5069-AEN2TR (discontinued)
|
3.011
|
--
|
|
1756-EN3TR/B
|
11.001
|
11.002 and later
|
For a full list of the potentially affected Rockwell Automation products and a description of the vulnerabilities and additional mitigations, see Knowledgebase Product Notice, CVE-2019-5096 and CVE 2019-5097 Vulnerabilities Impact Multiple Products.
MNRF/Assert can Occur on a Module After RCP Switchover (1955194)
|
Communication Modules
|
First Known in Firmware Revision
|
Corrected in Firmware Revision
|
|
1756-EN2T/D
|
10.006
|
12.001 and later
|
|
1756-EN2TR/C
|
10.007
|
12.001 and later
|
|
1756-EN3TR/B
|
10.007
|
12.001 and later
|
|
1756-EN2F/C
|
10.009
|
12.001 and later
|
|
1756-EN2TP/A
|
10.020
|
12.001 and later
|
After a switchover due to a cable break, the redundant system may not recover to a synchronized state. This can lead to the module experiencing a major nonrecoverable fault/assert.
A ReadSocket Service Request of the TCP/IP Socket Object Returns Incorrect Values (3096193)
|
Communication Modules
|
First Known in Firmware Revision
|
Corrected in Firmware Revision
|
|
1756-EN2T/D
|
10.006
|
12.001 and later
|
|
1756-EN2TR/C
|
10.007
|
12.001 and later
|
|
1756-EN3TR/B
|
10.007
|
12.001 and later
|
|
1756-EN2F/C
|
10.009
|
12.001 and later
|
|
1756-EN2TP/A
|
10.020
|
12.001 and later
|
When a Socket Object instance is used for a TCP connection, the response to a ReadSocket service request returns 0 for the Family, Port, and IP address.
Incorrect Product Type String in EDS files (3297343)
|
Communication Modules
|
First Known in Firmware Revision
|
Corrected in Firmware Revision
|
|
1756-EN2T/D
|
10.006
|
12.001 and later
|
|
1756-EN2TR/C
|
10.007
|
12.001 and later
|
|
1756-EN3TR/B
|
10.007
|
12.001 and later
|
|
1756-EN2F/C
|
10.009
|
12.001 and later
|
|
1756-EN2TP/A
|
10.020
|
12.001 and later
|
The ProdTypeStr keyword in EDS files had the incorrect value of ‘Communication Module’. The correct value is ‘Communications Module’.
Module does not get IP Address Assigned from a DHCP Server (2188094, 2233611)
|
Modules
|
First Known in Firmware
Revision
|
Corrected in Firmware
Revision
|
|
CompactLogix™ 5370
|
20.011
|
36.011
|
|
Compact GuardLogix®
5370
|
28.011
|
36.011
|
|
1756-EN2F
|
5.028 (Signed)
2.005 (Unsigned)
|
12.001 and later
|
|
1756-EN2T
|
5.028 (Signed)
|
12.001 and later
|
|
1756-EN2TP
|
10.020
|
12.001 and later
|
|
1756-EN2TR
|
5.028 (Signed)
1.003 (Unsigned)
|
12.001 and later
|
|
1756-EN3TR
|
5.028 (Signed)
3.004 (Unsigned)
|
12.001 and later
|
|
1756-ENBT
|
1.061
|
—
|
|
1768-ENBT
|
1.003
|
—
|
This anomaly was due to a change in the Dynamic Host Configuration Protocol (DHCP) standard, RFC 6842. This anomaly results in the module not being able to obtain an IP address through DHCP with some Stratix® switches that follow the updated standard.
For more information, see Knowledgebase Technote Some Ethernet devices do not obtain DHCP lease from Stratix 5800 as DHCP Server.
IP Address is Manually Configurable in DHCP Mode (1665460)
|
Communication Modules
|
First Known in Firmware Revision
|
Corrected in Firmware Revision
|
|
1756-EN2T/D
|
10.006
|
12.001 and later
|
|
1756-EN2TR/C
|
10.007
|
12.001 and later
|
|
1756-EN3TR/B
|
10.007
|
12.001 and later
|
|
1756-EN2F/C
|
10.009
|
12.001 and later
|
|
1756-EN2TP/A
|
10.020
|
12.001 and later
|
When a module is in DHCP mode, attempts to change the IP address manually are accepted, but the actual address remains the same.
Incorrect Delay Before Sending a Response to a Broadcast ListIdentity Request (1592443)
|
Communication Modules
|
First Known in Firmware Revision
|
Corrected in Firmware Revision
|
|
1756-EN2T/D
|
10.006
|
12.001 and later
|
|
1756-EN2TR/C
|
10.007
|
12.001 and later
|
|
1756-EN3TR/B
|
10.007
|
12.001 and later
|
|
1756-EN2F/C
|
10.009
|
12.001 and later
|
|
1756-EN2TP/A
|
10.020
|
12.001 and later
|
A module responds immediately to broadcast ListIdentity requests instead of delaying for a random period before responding.
Quick Change from BOOTP to DHCP is not reflected in the Module Settings (1489872)
|
Communication Modules
|
First Known in Firmware Revision
|
Corrected in Firmware Revision
|
|
1756-EN2T/D
|
10.006
|
12.001 and later
|
|
1756-EN2TR/C
|
10.007
|
12.001 and later
|
|
1756-EN3TR/B
|
10.007
|
12.001 and later
|
|
1756-EN2F/C
|
10.009
|
12.001 and later
|
|
1756-EN2TP/A
|
10.020
|
12.001 and later
|
After changing the module configuration from a Static IP address to BOOTP to DHCP in quick succession, the module uses the IP address obtained from the DHCP server, but the settings show an address obtained from the BOOTP server.
This happens when you:
PTP Announce Messages Have Incorrect PTP_TIMESCALE Value (1428782)
|
Communication Modules
|
First Known in Firmware Revision
|
Corrected in Firmware Revision
|
|
1756-EN2T/D
|
10.006
|
12.001 and later
|
|
1756-EN2TR/C
|
10.007
|
12.001 and later
|
|
1756-EN3TR/B
|
10.007
|
12.001 and later
|
|
1756-EN2F/C
|
10.009
|
12.001 and later
|
|
1756-EN2TP/A
|
10.020
|
12.001 and later
|
When a module is in the same chassis as the PTP Grandmaster, it sends PTP Announce Messages with an incorrect value for PTP_TIMESCALE.
Invalid IP Subnet Mask Allowed on Module (1418381)
|
Communication Modules
|
First Known in Firmware Revision
|
Corrected in Firmware Revision
|
|
1756-EN2T/D
|
10.006
|
12.001 and later
|
|
1756-EN2TR/C
|
10.007
|
12.001 and later
|
|
1756-EN3TR/B
|
10.007
|
12.001 and later
|
|
1756-EN2F/C
|
10.009
|
12.001 and later
|
|
1756-EN2TP/A
|
10.020
|
12.001 and later
|
The module does not check the validity of the subnet mask; therefore, an invalid subnet mask can be set on the module.
This release has the following functional changes from the previous release.
Dual Gateway
Functional Change Identified as of:
Firmware Revision 10.010, 1756-EN2TR/C, 1756-EN2TRK/C, 1756-EN2TRXT/C
Email Object and EtherNet/IP Socket Object
Functional Change Identified as of:
The Email Object and EtherNet/IP Socket Object can be disabled if they are not being used. For more information on how to disable these objects, see the following publications:
This release has the following application notes.
Web Page Layout
The web page layout includes the following changes: