Executive brief
Rockwell Automation industrial controllers are susceptible to a denial-of-service vulnerability that can be triggered remotely. An attacker can send a specially crafted project file to the device, causing it to enter a 'major non-recoverable fault' state. This effectively shuts down the controller and halts the industrial processes it manages until manual intervention or hardware recovery is performed.
Technical details
A classic buffer overflow vulnerability (CWE-120) exists in the firmware of Rockwell Automation 5370 and 5570 series controllers. The flaw is triggered when the device processes an invalid project file loaded by a remote user. Successful exploitation causes the controller to enter a Major Non-Recoverable Fault (MNRF) state, resulting in a complete denial of service. The vulnerability is reachable over the network without authentication. Rockwell Automation has released firmware versions V35.016 and V36.011 to remediate this issue.
Affected products
- Rockwell Automation CompactLogix 5370 V35.015 and earlier
- Rockwell Automation Compact GuardLogix 5370 V35.015 and earlier
- Rockwell Automation ControlLogix 5570 V35.015 and earlier
- Rockwell Automation GuardLogix 5570 V35.015 and earlier
Timeline
- 2026-07-14: advisory: Initial advisory release by Rockwell Automation (SD1781)
- 2026-07-14: patched: Corrected firmware versions V35.016 and V36.011 released