Executive brief
Rockwell Automation Logix controllers, which are used to manage industrial processes and machinery, are vulnerable to a denial-of-service attack. An attacker can send malicious file data to the controller, causing it to crash and enter a non-recoverable fault state. This would result in an immediate shutdown of the industrial equipment being controlled, potentially disrupting production or safety operations.
Technical details
A classic buffer overflow (CWE-120) exists in the firmware of Rockwell Automation 5380, 5480, and 5580 series controllers. The vulnerability is triggered when a malicious user writes invalid file data to the controller, likely via network-accessible services. Successful exploitation causes the device to enter a Major Non-Recoverable Fault (MNRF), effectively a permanent denial-of-service state until manual intervention or recovery procedures are performed. The issue is addressed in firmware versions V34.014, V35.013, and V36.011 or later.
Affected products
- Rockwell Automation CompactLogix 5380 V34.012 and earlier, V35.011 and earlier
- Rockwell Automation Compact GuardLogix 5380 V34.012 and earlier, V35.011 and earlier
- Rockwell Automation CompactLogix 5480 V34.012 and earlier, V35.011 and earlier
- Rockwell Automation ControlLogix 5580 V34.012 and earlier, V35.011 and earlier
- Rockwell Automation GuardLogix 5580 V34.012 and earlier, V35.011 and earlier
Timeline
- 2026-07-14: advisory
- 2026-07-14: patched