Executive brief
A vulnerability in the boot firmware of several Rockwell Automation industrial controllers could allow an attacker to crash the device. These controllers are used to manage complex industrial processes and safety systems. If exploited, the device enters a 'major non-recoverable fault,' requiring manual intervention and potentially causing significant downtime in manufacturing or utility operations.
Technical details
A classic buffer overflow (CWE-120) exists in the boot firmware of Rockwell Automation Logix controllers. The vulnerability is triggered when a malicious user writes invalid file data to the controller, likely via the network or a local interface. This results in a Major Non-Recoverable Fault (MNRF), effectively a permanent denial-of-service state until the device is recovered. The issue specifically affects the boot firmware (the low-level software that loads the main operating system). A fix is available in boot firmware version 1.072 or later, which is automatically included in device firmware versions V36.013 and V37.011.
Affected products
- Rockwell Automation CompactLogix 5380 Recovery Image before 1.072
- Rockwell Automation Compact GuardLogix 5380 Recovery Image before 1.072
- Rockwell Automation CompactLogix 5480 Recovery Image before 1.072
- Rockwell Automation ControlLogix 5580 Recovery Image before 1.072
- Rockwell Automation GuardLogix 5580 Recovery Image before 1.072
Timeline
- 2026-07-14: disclosed: Initial advisory release by Rockwell Automation
- 2026-07-14: patched: Corrected in boot firmware 1.072 and specific device firmware versions