Junglewise Threat Intelligence

CVE-2025-13823: Rockwell Automation Micro850/870 IPv6 stack denial of service

CVE-2025-13823 · Severity: info · CVSS 6.5 · Published 2025-12-15

Vendors: Rockwell Automation.

Executive brief

A vulnerability in the IPv6 networking stack of Rockwell Automation's Micro850 and Micro870 programmable logic controllers (PLCs) causes the controllers to enter a recoverable fault state when receiving multiple malformed IPv6 packets. An attacker with network access could trigger this fault condition, temporarily disrupting industrial automation operations until manual recovery actions are taken. This affects critical manufacturing and control systems that depend on these controllers.

Technical details

The vulnerability exists in the IPv6 stack implementation of Micro850 and Micro870 controllers (L50E/L70E variants, firmware V23.011). The root cause is a dependency on a vulnerable third-party IPv6 component (CWE-1395). When the controller receives multiple malformed IPv6 packets, improper validation or processing causes a recoverable fault with fault code 0xFE60. An unauthenticated attacker on the network can send crafted IPv6 packets to trigger this condition. While the fault is recoverable and does not cause permanent damage, it forces the controller into a fault state requiring manual recovery through fault clearing, effectively causing a denial of service. Firmware version V23.012 and above address this issue. Mitigation includes disabling IPv6 if not required.

Affected products

  • Rockwell Automation Micro850 V23.011 (L50E/L70E models affected; corrected in V23.012)
  • Rockwell Automation Micro870 V23.011 (L50E/L70E models affected; corrected in V23.012)

Timeline

  • 2025-12-09: disclosed: Rockwell Automation SD1766 advisory published
  • 2025-12-09: patched: Firmware V23.012 corrects the vulnerability in Micro850/870 L50E/L70E

References

Related threats