Junglewise Threat Intelligence

CVE-2025-12012: Rockwell Automation Logix Controllers buffer overflow in file handling

CVE-2025-12012 · Severity: info · CVSS 9.2 · Published 2026-07-14

Technologies: Rockwell Automation ControlLogix 5580, Rockwell Automation GuardLogix 5580, Rockwell Automation CompactLogix 5380. Vendors: Rockwell Automation.

Executive brief

Rockwell Automation Logix controllers, which are used to manage industrial processes and machinery, are vulnerable to a denial-of-service attack. An attacker can send malicious file data to the controller, causing it to crash and enter a non-recoverable fault state. This would result in an immediate shutdown of the industrial equipment being controlled, potentially disrupting production or safety operations.

Technical details

A classic buffer overflow (CWE-120) exists in the firmware of Rockwell Automation 5380, 5480, and 5580 series controllers. The vulnerability is triggered when a malicious user writes invalid file data to the controller, likely via network-accessible services. Successful exploitation causes the device to enter a Major Non-Recoverable Fault (MNRF), effectively a permanent denial-of-service state until manual intervention or recovery procedures are performed. The issue is addressed in firmware versions V34.014, V35.013, and V36.011 or later.

Affected products

  • Rockwell Automation CompactLogix 5380 V34.012 and earlier, V35.011 and earlier
  • Rockwell Automation Compact GuardLogix 5380 V34.012 and earlier, V35.011 and earlier
  • Rockwell Automation CompactLogix 5480 V34.012 and earlier, V35.011 and earlier
  • Rockwell Automation ControlLogix 5580 V34.012 and earlier, V35.011 and earlier
  • Rockwell Automation GuardLogix 5580 V34.012 and earlier, V35.011 and earlier

Timeline

  • 2026-07-14: advisory
  • 2026-07-14: patched

References

Related threats