Junglewise Threat Intelligence

CVE-2025-13824: Rockwell Automation Micro800 denial of service in CIP packet handling

CVE-2025-13824 · Severity: info · CVSS 8.7 · Published 2025-12-15

Vendors: Rockwell Automation.

Executive brief

Rockwell Automation's Micro800 series programmable logic controllers (PLCs) are compact devices used to control industrial machinery and equipment. A flaw in the handling of malformed CIP (Common Industrial Protocol) packets causes affected controllers to crash and become unresponsive, requiring a power cycle and manual fault recovery. In operational environments, this could disrupt factory automation and production lines.

Technical details

The vulnerability exists in improper validation of malformed CIP packets, classified as CWE-763 (Release of Invalid Pointer or Reference). When a Micro800 controller receives specially crafted malformed CIP packets, it enters a hard fault state with a solid red Fault LED and becomes completely unresponsive. Upon power cycle, the device enters a recoverable fault reporting fault code 0xF019. The attack vector is network-based (CIP protocol reception), requires no authentication, and can be triggered through normal protocol communication. The flaw affects Micro850/870 (L50E/L70E) v23.011 and below, Micro850/870 (LC50/LC70) v12.013 and lower, and Micro820 (LC20) v14.011 and lower; fixes are available in firmware v23.012 for L50E/L70E and migration paths for older models.

Affected products

  • Rockwell Automation Micro850 L50E v23.011 and below; LC50 v12.013 and lower
  • Rockwell Automation Micro870 L70E v23.011 and below; LC70 v12.013 and lower
  • Rockwell Automation Micro820 LC20 v14.011 and lower

Timeline

  • 2025-12-09: disclosed: Security advisory SD1766 published by Rockwell Automation
  • 2025-12-09: patched: Firmware v23.012 available for Micro850/870 L50E/L70E; migration path provided for older models

References

Related threats