Junglewise Threat Intelligence

CVE-2025-11694: Rockwell Automation CompactLogix DoS via CIP Improper Validation

CVE-2025-11694 · Severity: info · CVSS 8.7 · Published 2026-06-16

Vendors: Rockwell Automation.

Executive brief

Rockwell Automation CompactLogix 5370 controllers are modular automation devices used to control industrial machinery and motion systems. A vulnerability in how these controllers handle industrial communication protocols allows an attacker to remotely trigger a 'minor fault' state. This can disrupt manufacturing operations or machine-level processes, potentially leading to production downtime.

Technical details

A denial-of-service vulnerability exists in the 1769 CompactLogix 5370 series controllers due to missing validation of sequence numbers and source IP addresses within the Common Industrial Protocol (CIP) implementation. By leveraging Connection IDs (which may be exposed via the device's web diagnostic interface, as noted in related CVE-2026-9307), an unauthenticated remote attacker can inject malicious packets into existing sessions. This results in a 'minor fault' on the controller, impacting availability. The issue affects firmware version V36 and is corrected in version V38.011.

Affected products

  • Rockwell Automation CompactLogix 5370 L1 (1769-L1x) V36
  • Rockwell Automation CompactLogix 5370 L2 (1769-L2x) V36
  • Rockwell Automation CompactLogix 5370 L3 (1769-L3x) V36

Timeline

  • 2026-06-16: disclosed: Initial advisory release by Rockwell Automation
  • 2026-06-16: patched: Corrected in firmware version V38.011

References