Junglewise Threat Intelligence

CVE-2026-11317: Rockwell Automation Logix Controllers denial of service via CIP message

CVE-2026-11317 · Severity: info · CVSS 8.7 · Published 2026-06-16

Vendors: Rockwell Automation.

Executive brief

Rockwell Automation Logix controllers, which are used to manage industrial machinery and automation processes, are vulnerable to a denial-of-service attack. An attacker can send a specially crafted network message that causes the controller to crash into a 'Major Non-Recoverable Fault' state. This results in an immediate halt of industrial operations and requires a manual program reload to restore service, potentially leading to significant production downtime.

Technical details

A denial of service vulnerability exists in Rockwell Automation Logix 5370 and 5570 controllers due to improper resource handling (CWE-404) when processing Common Industrial Protocol (CIP) messages. An unauthenticated remote attacker can send a crafted CIP message over the network to trigger a Major Non-Recoverable Fault (MNRF). Devices with lower memory specifications are reported to be more susceptible to this condition. Once the fault occurs, the controller stops executing its logic, and recovery requires a fresh program download. Firmware updates (versions 34.016, 35.015, 36.012, 37.011 and later) have been released to address the issue.

Affected products

  • Rockwell Automation CompactLogix 5370 Prior to 34.016, 35.015, 36.012
  • Rockwell Automation Compact GuardLogix 5370 Prior to 34.016, 35.015, 36.012
  • Rockwell Automation ControlLogix 5570 Prior to 34.016, 35.015, 36.012
  • Rockwell Automation GuardLogix 5570 Prior to 34.016, 35.015, 36.012

Timeline

  • 2026-06-16: disclosed
  • 2026-06-16: advisory
  • 2026-06-16: patched

References

Related threats